Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID P1. You need to implement a solution that allows users to reset their own passwords without administrator intervention. The solution must also enforce a policy that requires users to verify their identity with two methods before resetting. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse Conditional Access MFA policies with SSPR's multi-method verification, not realizing that SSPR has its own separate configuration for the number of required verification methods, while Conditional Access policies apply to authentication events, not the password reset workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable self-service password reset (SSPR) and configure the number of methods required to reset to 2.

Self-service password reset (SSPR) in Microsoft Entra ID P1 allows users to reset their own passwords without administrator intervention. By configuring SSPR and setting the number of methods required to reset to 2, you enforce the policy that users must verify their identity with two authentication methods before resetting their password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure Privileged Identity Management (PIM) to require approval for password reset.

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to critical resources by providing just-in-time access to privileged roles. Its core function involves requiring activation and often approval for these elevated roles, ensuring that permissions are granted only when needed. PIM does not, however, offer functionality for end-users to reset their forgotten passwords; it is an access governance tool for administrative roles.

  • Create an Identity Protection user risk policy to force password reset.

    Why it's wrong here

    An Identity Protection user risk policy is a security control that detects potential compromises of user accounts, such as leaked credentials, and can automatically force a password reset as a remediation action. While effective for security, this policy forces a reset initiated by the system due to detected risk, rather than providing a mechanism for users to self-initiate a password reset when they simply forget their password. It's a reactive security measure, not a proactive self-service recovery tool.

  • Configure a Conditional Access policy to require MFA for password changes.

    Why it's wrong here

    Conditional Access policies are used to enforce specific access controls, such as requiring multi-factor authentication (MFA) or a compliant device, based on various conditions during sign-in or resource access. While a Conditional Access policy could secure the process of changing an existing password by requiring MFA, it does not provide the underlying functionality for a user to reset a forgotten password independently. It's an access enforcement engine, not a password recovery service.

  • Enable self-service password reset (SSPR) and configure the number of methods required to reset to 2.

    Why this is correct

    Enabling Microsoft Entra ID Self-Service Password Reset (SSPR) directly addresses the requirement for users to reset their forgotten passwords without administrator intervention. By configuring the number of authentication methods required to 2, the organization enhances the security of the reset process, ensuring that users provide multiple proofs of identity (e.g., mobile app notification and phone call) before gaining access. This feature is precisely designed for secure, user-initiated password recovery.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.