SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID to manage identities for employees and external partners. You need to ensure that external partners can access only specific applications and that their access expires automatically after 60 days. Which Microsoft Entra feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse the invitation and authentication capabilities of B2B collaboration (Option A) with the full lifecycle and access governance provided by entitlement management, assuming B2B alone can enforce time-bound application access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra entitlement management.
Microsoft Entra entitlement management allows you to create access packages that govern external partner access to specific applications, groups, and sites, with built-in time-limited access that automatically expires after a defined period (e.g., 60 days). This feature directly addresses the requirement to scope access to only specific applications and enforce automatic expiration, which is not natively handled by other Entra ID features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra B2B collaboration.
Why it's wrong here
Microsoft Entra B2B collaboration is designed for inviting external users to access your organization's resources and granting them initial access. While it facilitates guest user accounts and their access to specific applications or groups, B2B collaboration itself does not include built-in features for automatically expiring that access after a defined period. Access revocation for B2B guests typically requires manual intervention by an administrator.
- ✗
Conditional Access policies.
Why it's wrong here
Conditional Access policies evaluate various signals, such as user, device, location, and application, at the time an access request is made to determine whether to grant, block, or require additional authentication. These policies are effective for enforcing real-time access controls and security requirements, but they do not manage the duration of access or automatically revoke it after a set timeframe. Conditional Access governs *how* and *when* access is permitted, not *for how long*.
- ✗
Microsoft Entra Identity Protection.
Why it's wrong here
Microsoft Entra Identity Protection is a security tool focused on detecting and remediating identity-based risks, such as compromised credentials, suspicious sign-ins, or vulnerable user accounts. Its primary function is to protect identities from misuse by identifying threats and enforcing automated responses like requiring password changes or blocking sign-ins. Identity Protection does not provide capabilities for provisioning or deprovisioning access based on a time-limited schedule or managing access expiration.
- ✓
Microsoft Entra entitlement management.
Why this is correct
Microsoft Entra entitlement management is a robust identity governance feature specifically designed to manage the identity and access lifecycle for both internal and external users. It enables organizations to create access packages, which bundle resources like groups, applications, and SharePoint sites, and define policies that include mandatory access reviews and automatic expiration dates for assigned access. This capability directly addresses the requirement for assigning access and enforcing its automatic expiration.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.