SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that when a user's on-premises account is disabled, their cloud account is automatically disabled within 5 minutes. Which configuration should you use?
⚠ Common exam trap
It's easy for candidates to confuse identity synchronization (Entra Connect) with identity governance or access control tools like PIM or Conditional Access, which do not handle the propagation of on-premises account status changes to the cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect with directory sync configured for 5-minute sync interval
Microsoft Entra Connect with directory synchronization configured for a 5-minute sync interval ensures that changes made to on-premises Active Directory (such as disabling a user account) are replicated to Microsoft Entra ID within that interval. This meets the requirement of automatically disabling the cloud account within 5 minutes of the on-premises change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) for privileged roles. Its primary function involves requiring activation and approval workflows for elevated permissions. PIM does not facilitate or accelerate the synchronization of user account attributes, such as disabled status, from an on-premises Active Directory to Microsoft Entra ID; it operates on already synchronized identities.
- ✗
Microsoft Entra Conditional Access with session controls
Why it's wrong here
Microsoft Entra Conditional Access policies evaluate various conditions, including user, device, location, and application, to enforce access decisions like requiring multi-factor authentication or blocking access. While session controls can manage user sessions post-authentication, Conditional Access itself is an access policy engine, not a directory synchronization mechanism. It relies on the synchronized state of user accounts and their attributes from on-premises, rather than actively performing or accelerating the synchronization of account disabled status to Microsoft Entra ID.
- ✓
Microsoft Entra Connect with directory sync configured for 5-minute sync interval
Why this is correct
Microsoft Entra Connect is the foundational tool for synchronizing identities between an on-premises Active Directory and Microsoft Entra ID, including critical user account attributes like 'disabled' status. By default, the synchronization cycle runs every 30 minutes, but administrators can configure the Microsoft Entra Connect sync scheduler to run more frequently. This allows for a minimum 5-minute interval, ensuring that time-sensitive changes, such as account disablement, are reflected in the cloud promptly.
- ✗
Microsoft Entra Connect Health
Why it's wrong here
Microsoft Entra Connect Health is a monitoring service that provides a centralized view of the health, performance, and activity of your on-premises identity components, including Microsoft Entra Connect sync services. It offers crucial insights into synchronization errors, performance metrics, and operational status, helping administrators identify and troubleshoot issues. However, Connect Health is purely a diagnostic and reporting tool; it does not directly control, modify, or accelerate the synchronization schedule or frequency of Microsoft Entra Connect.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Microsoft Entra Connect
Microsoft Entra Connect is a tool that synchronizes on-premises Active Directory identities with Microsoft Entra ID (formerly Azure AD) to enable single sign-on and centralized identity management.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.