SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization wants to enable passwordless authentication for users. Which Microsoft Entra ID feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse Conditional Access (which can require passwordless methods as a grant control) with the actual feature that enables passwordless authentication, but Conditional Access only enforces policies, not the underlying authentication methods themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passwordless authentication methods
Passwordless authentication methods is the correct feature because it is the specific Microsoft Entra ID capability that allows users to sign in without a password, using methods such as Windows Hello for Business, the Microsoft Authenticator app, FIDO2 security keys, or phone sign-in. This directly enables the organization's goal of passwordless authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies define the rules for accessing resources, such as requiring multi-factor authentication (MFA) or blocking access from untrusted locations. While it can mandate the *use* of strong authentication methods, it does not directly enable or configure the underlying passwordless methods themselves. Its function is to evaluate conditions and enforce access controls based on existing authentication states and methods, not to provision new authentication types.
- ✗
Privileged Identity Management
Why it's wrong here
Azure AD Privileged Identity Management (PIM) is designed to manage, control, and monitor access to critical resources by providing just-in-time (JIT) and time-bound access to privileged roles. It helps mitigate the risks associated with standing administrative permissions by requiring activation and often multi-factor authentication for elevated privileges. PIM's scope is specifically privileged access governance, not the general enablement of user authentication methods like passwordless.
- ✗
Identity Protection
Why it's wrong here
Azure AD Identity Protection proactively detects, investigates, and remediates identity-based risks within an organization. It identifies vulnerabilities such as leaked credentials, detects suspicious sign-in behaviors, and flags risky users, subsequently integrating with Conditional Access to enforce automated remediation actions. While vital for securing identities, its primary function is risk management and response, not the direct configuration or deployment of authentication methods like passwordless options.
- ✓
Passwordless authentication methods
Why this is correct
Passwordless authentication methods, including Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator app, are the specific technologies that allow users to sign in without needing to type a password. These methods replace traditional passwords with more secure alternatives, significantly reducing the risk of phishing, credential stuffing, and brute-force attacks. Directly enabling and configuring these options within Microsoft Entra ID is the fundamental step to implement passwordless authentication for an organization's users.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Authenticator app
An authenticator app is a software application on your phone or computer that generates temporary codes used to prove your identity when logging into online accounts.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.