Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Entra ID for identity management. You need to require multi-factor authentication (MFA) for all users when accessing the Azure portal. Which feature should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy

Conditional Access policy (Option D) is correct because it allows you to create policies that enforce MFA for specific applications like the Azure portal. Option A, Privileged Identity Management, is used for managing and auditing privileged roles, not for enforcing MFA. Option B, Identity Protection user risk policy, can trigger MFA based on risk but cannot enforce MFA for all users unconditionally. Option C, an Entra ID P1 license, is a prerequisite for using Conditional Access but is not a feature itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. While PIM can integrate with Conditional Access to enforce MFA during the activation of a privileged role, its core function is not to enforce MFA for all users accessing general cloud applications as a standing policy. It focuses on reducing the exposure window for high-privilege accounts.

  • Identity Protection user risk policy

    Why it's wrong here

    An Identity Protection user risk policy is a reactive control that detects potential compromises of user identities, such as leaked credentials or unusual sign-in behaviors. When a user's risk level is elevated, these policies can trigger actions like requiring a password reset or multi-factor authentication. However, they are not designed to proactively enforce MFA for all users accessing specific cloud applications, irrespective of any detected risk. Their purpose is to mitigate existing or potential identity compromise.

  • Entra ID P1 license

    Why it's wrong here

    An Entra ID P1 license is a prerequisite for an organization to utilize advanced security features, including Conditional Access policies. While this license provides the entitlement to configure and deploy such policies, the license itself is not the mechanism that enforces multi-factor authentication. The actual enforcement of MFA for cloud applications is achieved through the specific configuration of a Conditional Access policy, which is enabled by the P1 license.

  • Conditional Access policy

    Why this is correct

    A Conditional Access policy is the precise tool within Microsoft Entra ID that allows administrators to enforce specific access requirements based on various conditions. By configuring a policy to target desired cloud applications and setting the grant control to "Require multi-factor authentication," the organization can mandate MFA for all users attempting to access those applications, thereby directly addressing the requirement to enforce MFA for cloud apps.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.