Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID and wants to enforce multi-factor authentication (MFA) for all users. Which policy should you create?

⚠ Common exam trap

Many candidates confuse Security defaults (a simple, pre-configured baseline) with a customizable policy, but Security defaults is not a policy you 'create'—it is an all-or-nothing toggle that cannot be scoped or modified, whereas Conditional Access policies are the correct, granular tool for enforcing MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy

Conditional Access policies are the correct mechanism to enforce MFA for all users because they allow granular, policy-driven access controls based on signals like user, location, device, and application. By creating a Conditional Access policy that requires MFA for all cloud apps, you can target all users and enforce MFA at authentication time, providing a flexible and scalable solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access policy

    Why this is correct

    Conditional Access policies are the primary method in Microsoft Entra ID for enforcing granular access controls, including multi-factor authentication (MFA). They evaluate conditions such as user, device, location, and application to determine if access should be granted, blocked, or require additional authentication methods like MFA, making them highly flexible for enforcing specific security requirements across an organization.

  • Identity Protection policy

    Why it's wrong here

    Microsoft Entra ID Protection policies are designed to detect and remediate identity-based risks, such as compromised credentials or unusual sign-in patterns. While they can enforce MFA as a remediation action when a risk is detected, their primary function is risk detection and response, not the proactive, blanket enforcement of MFA for all users or specific groups under normal operating conditions.

  • Security defaults

    Why it's wrong here

    Security defaults provide a baseline level of security for all tenants by enforcing multi-factor authentication for all users and requiring administrators to register for MFA. However, they are a simple on/off setting without the granularity to define specific conditions, exclusions, or target particular applications or user groups, making them less suitable for complex organizational requirements than Conditional Access.

  • Privileged Identity Management

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. Its core function is to provide just-in-time and just-enough access to privileged roles, often requiring MFA during the role activation process, but it does not serve as the general mechanism for enforcing MFA for all user sign-ins across an organization.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.