SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID with P2 licenses. You need to delegate the ability to manage role assignments in Entra ID without granting global admin rights. Which feature should you use?
⚠ Common exam trap
Many candidates confuse Administrative Units (which limit scope) with Privileged Identity Management (which manages role assignment delegation and activation), as both deal with role management but serve different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management
Privileged Identity Management (PIM) in Microsoft Entra ID P2 enables just-in-time, time-bound, and approval-based role assignments, allowing you to delegate role management without granting permanent global admin rights. PIM provides role activation workflows and auditing, making it the correct feature for delegating role assignment management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Entitlement Management
Why it's wrong here
Entitlement Management, a feature within Microsoft Entra Identity Governance, is designed to manage access to groups, applications, and SharePoint sites for both internal and external users through the creation of access packages. While these access packages can grant membership to groups that might be assigned roles, its primary function is not the direct delegation or management of Microsoft Entra administrative roles. It focuses on automating the lifecycle of access requests, approvals, and reviews for specific resource entitlements.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies in Microsoft Entra ID define specific conditions that must be met before users can access applications and services, such as requiring multi-factor authentication, device compliance, or trusted network locations. These policies act as an enforcement engine, determining how and when access is granted based on various signals. However, Conditional Access is not a tool for delegating the management of administrative roles or assigning them to users; it's purely a control mechanism for access policies.
- ✗
Administrative Units
Why it's wrong here
Administrative Units (AUs) provide a way to logically group Microsoft Entra resources, such as users and groups, and then scope administrative permissions to only those resources. While AUs enable granular delegation by restricting an administrator's authority to manage objects within their assigned unit, they do not facilitate the delegation of role assignment management itself. An administrator assigned to an AU can manage users within it, but they cannot assign or manage Microsoft Entra roles for those users unless they also hold a role like User Administrator (scoped to the AU).
- ✓
Privileged Identity Management
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is the correct solution for managing, controlling, and monitoring access to important resources within Microsoft Entra ID and other Microsoft online services. PIM specifically enables just-in-time (JIT) access to roles, time-bound assignments, and approval workflows for role activation. It allows organizations to delegate the management of role assignments, including the ability for designated users to assign eligible roles to others, thereby significantly reducing the standing access of highly privileged accounts.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.