SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID P2 and wants to reduce the risk of identity compromise by requiring multifactor authentication (MFA) for all users, but excluding users when they are on the corporate network. Which policy type should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy
Conditional Access policies allow you to enforce MFA based on network location, user, and device conditions. Option A is correct because the policy can target all users and exclude trusted IPs (e.g., the corporate network). Option B is wrong because self-service password reset (SSPR) does not enforce MFA. Option C is wrong because Identity Protection detects risk but does not directly enforce MFA by location. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time access for privileged roles, not general MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy
Why this is correct
Microsoft Entra Conditional Access policies are the primary mechanism for enforcing access controls based on specific conditions, such as user location, device state, or application being accessed. By defining a policy that targets all users and requires MFA, an administrator can then create an exception for trusted IP ranges, effectively bypassing MFA when users are on the corporate network. This granular control over access based on real-time signals is central to Microsoft Entra ID P2 security capabilities.
- ✗
Self-service password reset (SSPR) policy
Why it's wrong here
Self-service password reset (SSPR) is a feature that empowers users to securely reset their forgotten passwords without requiring administrator assistance. While SSPR itself can leverage multi-factor authentication for identity verification *during* the password reset process, its policy configuration does not govern or enforce MFA as a general sign-in requirement for users accessing applications or services. SSPR policies are focused solely on the mechanics and requirements for password resets.
- ✗
Identity Protection risk policy
Why it's wrong here
Microsoft Entra ID Protection policies are specifically designed to detect and respond to identity-based risks, such as impossible travel, sign-ins from infected devices, or leaked credentials. These policies trigger actions like requiring MFA or a password change *only when a risk is detected*, rather than enforcing access controls based on static conditions like network location. Therefore, an ID Protection policy cannot be configured to universally require MFA for all users except those from trusted IPs.
- ✗
Privileged Identity Management (PIM) activation policy
Why it's wrong here
Privileged Identity Management (PIM) is a service within Microsoft Entra ID that enables organizations to manage, control, and monitor access to important resources by providing just-in-time and just-enough access. PIM policies govern the *activation* of eligible roles, often requiring MFA or justification during the elevation process itself, but they do not enforce MFA as a general sign-in requirement for all users accessing applications. Its scope is limited to the lifecycle and activation of privileged roles, not general user sign-in policies.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.