Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID with P2 licenses. You need to implement a policy that requires users to perform multifactor authentication (MFA) when accessing the finance application from an untrusted network, but not when accessing it from the corporate network. Which Microsoft Entra feature should you configure?

⚠ Common exam trap

Candidates often confuse the MFA registration policy (which only ensures users have registered MFA methods) with a Conditional Access policy that actually enforces MFA during sign-in based on conditions like network location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Conditional Access policy

Microsoft Entra Conditional Access policies allow you to enforce MFA based on conditions such as network location. By configuring a policy that targets the finance application and includes a condition for 'untrusted networks' (e.g., any location other than the corporate network's trusted IP ranges), you can require MFA only when access originates from outside the corporate network. This is the correct feature for granular, condition-based access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Entitlement Management

    Why it's wrong here

    Microsoft Entra Entitlement Management is primarily designed for governing the identity and access lifecycle, enabling organizations to manage access to resources through self-service access packages, approval workflows, and access reviews. Its core function is to ensure users have the right access for the right duration, not to enforce authentication methods like Multi-Factor Authentication (MFA) during the sign-in process itself. Therefore, it cannot directly enforce MFA based on network location.

  • Microsoft Entra ID Protection MFA registration policy

    Why it's wrong here

    The Microsoft Entra ID Protection MFA registration policy is specifically engineered to prompt users who have not yet registered for Multi-Factor Authentication to complete their registration. This policy ensures that users are enrolled in MFA, making it available for future use, but it does not actively enforce MFA as a requirement for every sign-in attempt or based on specific conditions like network location. Its scope is limited to registration, not ongoing authentication enforcement.

  • Microsoft Entra Conditional Access policy

    Why this is correct

    Microsoft Entra Conditional Access policies are powerful 'if-then' statements that evaluate various signals, such as user, device, location, and application, to make real-time access decisions. By configuring a Conditional Access policy, an organization can specify conditions (e.g., users signing in from untrusted networks) and then enforce specific controls, such as requiring Multi-Factor Authentication, before granting access to resources. This capability directly addresses the need to enforce MFA during sign-in based on location.

  • Microsoft Entra Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is a service focused on managing, controlling, and monitoring access to important resources within an organization, particularly for privileged roles. PIM enables just-in-time and just-enough access, requiring users to activate roles and often enforcing MFA during that activation process. However, PIM's scope is limited to privileged role activation and management, not providing a general mechanism to enforce MFA for all user sign-ins or based on network location for non-privileged access.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.