SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Your organization wants to use Microsoft Entra ID to provide single sign-on (SSO) for a third-party SaaS application. What must you configure in Microsoft Entra ID?
⚠ Common exam trap
SC-900 often tests the confusion between Conditional Access and enterprise application registration; candidates may think Conditional Access alone enables SSO, but it only enforces access policies after SSO is configured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enterprise application registration
To provide SSO for a third-party SaaS application using Microsoft Entra ID, you must configure an enterprise application registration, which represents the application in your tenant and enables SAML or OIDC-based SSO. This registration includes the necessary configuration for single sign-on, such as the reply URL and claims.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection policy
Why it's wrong here
Identity Protection detects and responds to risky sign-ins and compromised credentials; it establishes no SSO trust with a third-party SaaS application. It is tempting because it is a headline Microsoft Entra ID security capability, and would be correct when the requirement is automated risk-based conditional access rather than federated single sign-on.
- ✗
Conditional Access policy
Why it's wrong here
SSO to a third-party SaaS app requires configuring an enterprise application (gallery or custom SAML/OIDC) and assigning users; Conditional Access only enforces access controls on sign-ins after that app exists. It is tempting because Conditional Access governs sign-in risk and device compliance, and would be correct when you must restrict access to an already-integrated application.
- ✓
Enterprise application registration
Why this is correct
Registering the SaaS application as an enterprise application in Microsoft Entra ID creates the service principal and trust configuration needed for SAML or OIDC federation. This enables single sign-on and lets you assign users and configure claims for the third-party service.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset lets users reset their own credentials; it configures no federation or SSO trust with a SaaS application. It is tempting because it reduces helpdesk load and is a common Entra ID feature, and would be correct when the requirement is delegated password management rather than single sign-on.
Go deeper
Related to this question
Learn chapter
Cross-Tenant Access Settings
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
SSO
Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications or systems with one set of login credentials.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.