SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company is implementing Microsoft Entra ID and wants to ensure that users can sign in using their existing social media accounts. Which feature should you configure?
⚠ Common exam trap
Watch out — candidates often confuse B2B collaboration (which is for business partners) with External Identities (which includes social identity providers), because both involve external users, but only External Identities supports social login providers like Google and Facebook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External Identities
External Identities in Microsoft Entra ID allows you to configure identity providers for social media accounts (e.g., Google, Facebook) so users can sign in with their existing credentials. This is done by enabling federation with social identity providers via the External Identities blade, which uses OAuth 2.0 and OpenID Connect protocols to authenticate users without creating a separate Microsoft account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
B2B collaboration
Why it's wrong here
B2B collaboration in Microsoft Entra ID allows organizations to invite external users from other Entra ID tenants or specific email addresses to access their resources. While it facilitates external access, its primary focus is on business-to-business scenarios, enabling collaboration with partners, suppliers, and vendors. It is not designed for enabling general consumer sign-in using social identity providers like Google or Facebook for public-facing applications.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a policy-based access control engine within Microsoft Entra ID that enforces specific requirements before granting access to resources. It evaluates conditions such as user location, device compliance, or sign-in risk, then applies actions like multi-factor authentication or blocking access. However, Conditional Access does not provide the underlying mechanism for external users to sign in; it only governs *how* they can access resources once their identity is established and authenticated.
- ✓
External Identities
Why this is correct
Microsoft Entra External Identities is the comprehensive set of capabilities that allows organizations to manage all external users, including customers, partners, and citizens. It specifically supports enabling sign-in for consumers using social identity providers like Google, Facebook, and Microsoft accounts, as well as enterprise identity providers, allowing them to access applications and resources securely. This feature is crucial for scenarios requiring consumer-facing applications where users bring their own social identities.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security module focused on detecting, investigating, and remediating identity-based risks. It identifies suspicious actions related to user accounts and sign-ins, such as leaked credentials, impossible travel, or unfamiliar sign-in properties, and can trigger automated responses like requiring password changes or MFA. While vital for enhancing security, Identity Protection does not provide the functionality to onboard or enable external users to sign in to an organization's applications.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Federation
Federation is a system that lets you use one set of login credentials (like your work email and password) to access resources across different organizations or services without needing separate accounts for each one.
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.