SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company wants to provide a single sign-on experience for all cloud applications. Which Microsoft Entra ID feature should you implement?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access (a policy enforcement tool) with SSO configuration, or they mistakenly think B2B collaboration is needed for internal app SSO, when in fact App registration and SSO configuration is the correct feature for enabling a unified sign-on experience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App registration and SSO configuration
App registration and SSO configuration in Microsoft Entra ID enables single sign-on (SSO) by registering each cloud application as an enterprise application and configuring federation protocols such as SAML 2.0, OpenID Connect, or OAuth 2.0. This allows users to authenticate once with their Entra ID credentials and access all configured cloud applications without repeated logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
B2B collaboration
Why it's wrong here
Microsoft Entra B2B collaboration is designed for inviting external users, such as partners or customers, to access an organization's resources using their own identities. While it provides a form of single sign-on for these guest users within the inviting tenant, its primary function is external user management, not establishing a single sign-on experience for the company's own internal employees across their suite of applications.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature focused on detecting, investigating, and remediating identity-based risks within an organization. It analyzes sign-in attempts and user behavior to identify potential compromises, such as leaked credentials or unusual sign-in locations, and can enforce automated responses like requiring multi-factor authentication. Its role is entirely about risk detection and mitigation, not enabling or configuring single sign-on for applications.
- ✓
App registration and SSO configuration
Why this is correct
App registration in Microsoft Entra ID is the essential process for integrating an application to use Entra ID as its identity provider. By registering an application, administrators define how users authenticate, grant necessary permissions, and configure single sign-on (SSO) protocols like OpenID Connect or SAML. This direct integration enables users to access the registered application seamlessly using their existing Entra ID credentials without re-entering them, thereby providing a unified SSO experience.
- ✗
Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access policies are used to enforce specific access requirements *after* a user has successfully authenticated. These policies evaluate various signals, such as user location, device compliance, or sign-in risk, to determine if additional controls like multi-factor authentication or device restrictions are needed before granting access to an application. While crucial for security, Conditional Access does not establish or configure the single sign-on mechanism itself; it merely governs the conditions under which that SSO access is permitted.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Federation
Federation is a system that lets you use one set of login credentials (like your work email and password) to access resources across different organizations or services without needing separate accounts for each one.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.