Courseiva
Describe the capabilities of Microsoft EntramediumMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID P2 and wants to reduce the risk of identity compromise by requiring multifactor authentication (MFA) for all users, but excluding users when they are on the corporate network. Which policy type should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy

Conditional Access policies allow you to enforce MFA based on network location, user, and device conditions. Option A is correct because the policy can target all users and exclude trusted IPs (e.g., the corporate network). Option B is wrong because self-service password reset (SSPR) does not enforce MFA. Option C is wrong because Identity Protection detects risk but does not directly enforce MFA by location. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time access for privileged roles, not general MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conditional Access policy

    Why this is correct

    Microsoft Entra Conditional Access policies are the primary mechanism for enforcing access controls based on specific conditions, such as user location, device state, or application being accessed. By defining a policy that targets all users and requires MFA, an administrator can then create an exception for trusted IP ranges, effectively bypassing MFA when users are on the corporate network. This granular control over access based on real-time signals is central to Microsoft Entra ID P2 security capabilities.

  • Self-service password reset (SSPR) policy

    Why it's wrong here

    Self-service password reset (SSPR) is a feature that empowers users to securely reset their forgotten passwords without requiring administrator assistance. While SSPR itself can leverage multi-factor authentication for identity verification *during* the password reset process, its policy configuration does not govern or enforce MFA as a general sign-in requirement for users accessing applications or services. SSPR policies are focused solely on the mechanics and requirements for password resets.

  • Identity Protection risk policy

    Why it's wrong here

    Microsoft Entra ID Protection policies are specifically designed to detect and respond to identity-based risks, such as impossible travel, sign-ins from infected devices, or leaked credentials. These policies trigger actions like requiring MFA or a password change *only when a risk is detected*, rather than enforcing access controls based on static conditions like network location. Therefore, an ID Protection policy cannot be configured to universally require MFA for all users except those from trusted IPs.

  • Privileged Identity Management (PIM) activation policy

    Why it's wrong here

    Privileged Identity Management (PIM) is a service within Microsoft Entra ID that enables organizations to manage, control, and monitor access to important resources by providing just-in-time and just-enough access. PIM policies govern the *activation* of eligible roles, often requiring MFA or justification during the elevation process itself, but they do not enforce MFA as a general sign-in requirement for all users accessing applications. Its scope is limited to the lifecycle and activation of privileged roles, not general user sign-in policies.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.