SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) for all users. Which policy should you create?
⚠ Common exam trap
Many candidates confuse Security defaults (a simple, pre-configured baseline) with a customizable policy, but Security defaults is not a policy you 'create'—it is an all-or-nothing toggle that cannot be scoped or modified, whereas Conditional Access policies are the correct, granular tool for enforcing MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy
Conditional Access policies are the correct mechanism to enforce MFA for all users because they allow granular, policy-driven access controls based on signals like user, location, device, and application. By creating a Conditional Access policy that requires MFA for all cloud apps, you can target all users and enforce MFA at authentication time, providing a flexible and scalable solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy
Why this is correct
Conditional Access policies are the primary method in Microsoft Entra ID for enforcing granular access controls, including multi-factor authentication (MFA). They evaluate conditions such as user, device, location, and application to determine if access should be granted, blocked, or require additional authentication methods like MFA, making them highly flexible for enforcing specific security requirements across an organization.
- ✗
Identity Protection policy
Why it's wrong here
Microsoft Entra ID Protection policies are designed to detect and remediate identity-based risks, such as compromised credentials or unusual sign-in patterns. While they can enforce MFA as a remediation action when a risk is detected, their primary function is risk detection and response, not the proactive, blanket enforcement of MFA for all users or specific groups under normal operating conditions.
- ✗
Security defaults
Why it's wrong here
Security defaults provide a baseline level of security for all tenants by enforcing multi-factor authentication for all users and requiring administrators to register for MFA. However, they are a simple on/off setting without the granularity to define specific conditions, exclusions, or target particular applications or user groups, making them less suitable for complex organizational requirements than Conditional Access.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its core function is to provide just-in-time and just-enough access to privileged roles, often requiring MFA during the role activation process, but it does not serve as the general mechanism for enforcing MFA for all user sign-ins across an organization.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.