SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company uses Microsoft Entra ID with P2 licenses. You want to require approval for users to activate the Global Administrator role. Which feature should you configure?
⚠ Common exam trap
Many candidates confuse Conditional Access (which controls sign-in conditions) with PIM's approval workflow, but Conditional Access cannot enforce a multi-step approval process for role activation; only PIM provides that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time privileged access, including the ability to require approval for role activation. By configuring PIM for the Global Administrator role, you can enforce that users must request activation and receive approval before gaining the role's permissions, ensuring least-privilege and auditability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. It enables approval workflows for role activation, requiring users to request elevation and obtain approval before gaining temporary administrative rights. This directly addresses the need for a controlled and auditable process for activating privileged roles.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature focused on detecting potential vulnerabilities affecting an organization's identities and identifying risky sign-ins or users. It leverages machine learning to detect threats like leaked credentials, impossible travel, or unfamiliar sign-in properties, and can automate responses such as requiring MFA or blocking access. However, Identity Protection does not provide a mechanism for managing or approving the activation of administrative roles; its primary function is risk detection and remediation.
- ✗
Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access policies enforce specific conditions before granting access to applications and services, acting as an 'if-then' statement for access control. These policies can require multi-factor authentication, compliant devices, or specific network locations based on user, application, or device context. While powerful for controlling access to resources, Conditional Access does not directly manage the activation of elevated administrative roles or incorporate an approval workflow for such temporary privilege elevations.
- ✗
Access reviews
Why it's wrong here
Microsoft Entra access reviews are a governance tool used to periodically review who has access to specific resources, such as group memberships or application assignments, to ensure only authorized users maintain access. They help organizations manage stale access rights and meet compliance requirements by prompting reviewers to confirm or deny continued access. However, access reviews are a post-provisioning evaluation mechanism and do not provide an approval workflow for the just-in-time activation of privileged roles.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.