Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Exhibit

Refer to the exhibit.

```powershell
Get-AzureADPolicy | Where-Object {$_.Type -eq "TokenLifetimePolicy"}
```

You run the following PowerShell command in your Microsoft Entra ID environment:

Get-AzureADPolicy -Type TokenLifetimePolicy

What is the command retrieving?

⚠ Common exam trap

SC-900 often tests whether candidates can distinguish the specific Microsoft Entra ID PowerShell cmdlet outputs — candidates confuse Get-AzureADPolicy with conditional access or role cmdlets because all are 'policy-like' governance objects in Entra ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Token lifetime policies

The cmdlet Get-AzureADPolicy with the -Type parameter set to TokenLifetimePolicy retrieves the token lifetime policies configured in Microsoft Entra ID (formerly Azure AD). These policies control how long access tokens, ID tokens, and refresh tokens remain valid before requiring re-authentication. This is part of the legacy Microsoft Entra ID PowerShell module used to manage organizational token configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conditional access policies

    Why it's wrong here

    Conditional access policies are separate objects, retrieved with Get-AzureADMSConditionalAccessPolicy, not TokenLifetimePolicy. The cmdlet returns token lifetime definitions controlling access, ID and refresh token expiry. Conditional access is the right target when enforcing sign-in controls such as MFA or device compliance for specific users and cloud apps.

  • ✗

    Named locations

    Why it's wrong here

    Named locations are conditional access constructs, retrieved through Get-AzureADMSNamedLocationPolicy, not TokenLifetimePolicy. This cmdlet returns token lifetime definitions governing access, ID and refresh token expiry. Named locations are the correct object when defining trusted IP ranges or countries for conditional access sign-in evaluation.

  • ✗

    Role assignments

    Why it's wrong here

    TokenLifetimePolicy objects define how long access, ID and refresh tokens remain valid; they contain no role assignment data. Role assignments are held in directory role definitions and assignments, retrieved via Get-AzureADDirectoryRole and Get-AzureADDirectoryRoleMember, which suits auditing who holds privileged Entra roles.

  • ✓

    Token lifetime policies

    Why this is correct

    The `-Type TokenLifetimePolicy` parameter filters the returned objects to token lifetime policies, which control how long access, ID and refresh tokens remain valid before expiry. This directly satisfies the stem's request to retrieve token lifetime policies from Microsoft Entra ID, rather than other policy types such as application or consent policies.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.