SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID P2 and wants to reduce the risk of identity compromise by requiring multifactor authentication (MFA) for all users, but excluding users when they are on the corporate network. Which policy type should you configure?
⚠ Common exam trap
SC-900 often tests the confusion between Conditional Access and Identity Protection risk policies, where the latter is for risk-based automation, not location-based MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy
Conditional Access policies in Microsoft Entra ID allow you to enforce MFA based on conditions such as user group, location, device, and application. You can create a policy that requires MFA for all users but excludes trusted corporate network locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy
Why this is correct
Microsoft Entra Conditional Access policies are the primary mechanism for enforcing access controls based on specific conditions, such as user location, device state, or application being accessed. By defining a policy that targets all users and requires MFA, an administrator can then create an exception for trusted IP ranges, effectively bypassing MFA when users are on the corporate network. This granular control over access based on real-time signals is central to Microsoft Entra ID P2 security capabilities.
- ✗
Self-service password reset (SSPR) policy
Why it's wrong here
Self-service password reset (SSPR) is a feature that empowers users to securely reset their forgotten passwords without requiring administrator assistance. While SSPR itself can leverage multi-factor authentication for identity verification *during* the password reset process, its policy configuration does not govern or enforce MFA as a general sign-in requirement for users accessing applications or services. SSPR policies are focused solely on the mechanics and requirements for password resets.
- ✗
Identity Protection risk policy
Why it's wrong here
Microsoft Entra ID Protection policies are specifically designed to detect and respond to identity-based risks, such as impossible travel, sign-ins from infected devices, or leaked credentials. These policies trigger actions like requiring MFA or a password change *only when a risk is detected*, rather than enforcing access controls based on static conditions like network location. Therefore, an ID Protection policy cannot be configured to universally require MFA for all users except those from trusted IPs.
- ✗
Privileged Identity Management (PIM) activation policy
Why it's wrong here
Privileged Identity Management (PIM) is a service within Microsoft Entra ID that enables organizations to manage, control, and monitor access to important resources by providing just-in-time and just-enough access. PIM policies govern the *activation* of eligible roles, often requiring MFA or justification during the elevation process itself, but they do not enforce MFA as a general sign-in requirement for all users accessing applications. Its scope is limited to the lifecycle and activation of privileged roles, not general user sign-in policies.
Go deeper
Related to this question
Learn chapter
Entra Internet Access and Private Access
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.