SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID P2 licenses. You need to implement a process to automatically remove users from a group if they have not signed in for 90 days. Which feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Access Reviews (which handle membership lifecycle based on inactivity) with Conditional Access (which controls access at sign-in) or Privileged Identity Management (which focuses on privileged roles).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews in Identity Governance
Access reviews in Identity Governance allow you to automate the review and removal of group memberships based on inactivity criteria, such as users who haven't signed in for 90 days. This feature is specifically designed for periodic attestation and lifecycle management of group memberships, leveraging Microsoft Entra ID P2 licenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policy
Why it's wrong here
Conditional Access policies are designed to enforce access controls in real-time based on specific conditions like user location, device compliance, or sign-in risk. While they can block or grant access, or require multi-factor authentication, they do not possess functionality to modify group memberships or automatically remove users from groups due to inactivity. Their role is to govern *how* access is granted, not *who* is a member of a group.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources by providing just-in-time (JIT) and just-enough-access (JEA). PIM primarily applies to Microsoft Entra roles, Azure resource roles, and groups assigned to roles, allowing for temporary elevation of privileges. It does not provide a mechanism to automatically remove inactive users from standard security or Microsoft 365 groups that are not assigned to a privileged role.
- ✓
Access reviews in Identity Governance
Why this is correct
Access reviews, a core component of Microsoft Entra Identity Governance, enable organizations to efficiently manage group memberships, application access, and role assignments. They allow administrators or group owners to periodically review who has access to what, and crucially, can be configured to automatically remove users from groups if they fail to attest to their continued need for access or if they are identified as inactive based on sign-in data. This capability directly addresses the requirement to maintain clean group memberships by removing inactive users.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a security feature focused on detecting, investigating, and remediating identity-based risks within an organization. It identifies suspicious activities such as impossible travel, leaked credentials, or sign-ins from unfamiliar locations, and can enforce automated responses like requiring multi-factor authentication or blocking access. However, ID Protection's primary function is risk detection and response, not the lifecycle management of group memberships or the automatic removal of inactive users from groups.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.