Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Your organization wants to use Microsoft Entra ID to provide single sign-on (SSO) for a third-party SaaS application. What must you configure in Microsoft Entra ID?

⚠ Common exam trap

SC-900 often tests the confusion between Conditional Access and enterprise application registration; candidates may think Conditional Access alone enables SSO, but it only enforces access policies after SSO is configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enterprise application registration

To provide SSO for a third-party SaaS application using Microsoft Entra ID, you must configure an enterprise application registration, which represents the application in your tenant and enables SAML or OIDC-based SSO. This registration includes the necessary configuration for single sign-on, such as the reply URL and claims.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity Protection policy

    Why it's wrong here

    Identity Protection detects and responds to risky sign-ins and compromised credentials; it establishes no SSO trust with a third-party SaaS application. It is tempting because it is a headline Microsoft Entra ID security capability, and would be correct when the requirement is automated risk-based conditional access rather than federated single sign-on.

  • ✗

    Conditional Access policy

    Why it's wrong here

    SSO to a third-party SaaS app requires configuring an enterprise application (gallery or custom SAML/OIDC) and assigning users; Conditional Access only enforces access controls on sign-ins after that app exists. It is tempting because Conditional Access governs sign-in risk and device compliance, and would be correct when you must restrict access to an already-integrated application.

  • ✓

    Enterprise application registration

    Why this is correct

    Registering the SaaS application as an enterprise application in Microsoft Entra ID creates the service principal and trust configuration needed for SAML or OIDC federation. This enables single sign-on and lets you assign users and configure claims for the third-party service.

  • ✗

    Self-service password reset

    Why it's wrong here

    Self-service password reset lets users reset their own credentials; it configures no federation or SSO trust with a SaaS application. It is tempting because it reduces helpdesk load and is a common Entra ID feature, and would be correct when the requirement is delegated password management rather than single sign-on.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.