SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization uses Microsoft Entra ID. You want to provide external partners with access to a SharePoint site using their own identity providers (e.g., Google, Facebook). Which feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse the primary use cases of Microsoft Entra B2B collaboration and Microsoft Entra External ID (B2C). While both deal with external identities and can involve social identity providers, B2B collaboration is designed for inviting guest users (often partners or collaborators) to access organizational resources like SharePoint within your existing Entra ID tenant. B2C, on the other hand, is for customer-facing applications where you manage consumer identities in a separate B2C tenant. Candidates might incorrectly assume B2C is needed because of the mention of social identities, overlooking that B2B also supports Google and Facebook federation for guest access to internal resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra B2B collaboration
Microsoft Entra B2B collaboration allows you to invite external users (guests) to your Microsoft Entra ID tenant and grant them access to your organization's resources, such as SharePoint sites. B2B supports various identity providers for guest users, including other Microsoft Entra ID tenants, Microsoft accounts, email one-time passcodes, and crucially, social identity providers like Google and Facebook. By configuring federation with these social providers, external partners can use their existing Google or Facebook accounts to sign in as guests and access the SharePoint site. Microsoft Entra External ID (B2C) is primarily designed for customer-facing applications and managing consumer identities in a separate tenant, not for directly granting partners access to internal resources like SharePoint within the main Entra ID tenant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra B2B collaboration
Why this is correct
Microsoft Entra B2B collaboration is designed for inviting external users from other organizations who already possess a Microsoft Entra ID account or a Microsoft account. It facilitates resource sharing and collaboration with partners, but it does not natively support consumer-facing applications needing to authenticate users via social identity providers like Google or Facebook. Therefore, it is not suitable for scenarios requiring broad social login integration for a customer base.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is a security feature focused on detecting and remediating identity-based risks within your Microsoft Entra ID tenant. It identifies vulnerabilities, risky sign-ins, and compromised user accounts by analyzing various signals. This service enhances security posture but does not provide core identity management capabilities or integrate external identity providers for user authentication in applications.
- ✗
Microsoft Entra External ID (B2C)
Why it's wrong here
Microsoft Entra External ID (B2C) is a comprehensive customer identity and access management (CIAM) solution specifically designed for consumer-facing web and mobile applications. It allows organizations to manage millions of customer identities and supports a wide range of authentication options, including local accounts, enterprise accounts, and popular social identity providers like Google, Facebook, and X (formerly Twitter). This makes it the ideal choice for providing flexible authentication experiences for external users without existing organizational identities.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies in Microsoft Entra ID are powerful tools for enforcing access controls to applications and resources based on specific conditions after a user has successfully authenticated. These policies evaluate factors such as user location, device compliance, and sign-in risk to grant or block access, or require additional authentication steps. However, Conditional Access does not function as an identity provider itself nor does it facilitate the integration of external identity providers for the initial authentication process.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Global Secure Access
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.