Exam objective

SC-900

Describe access management capabilities of Microsoft Entra ID

This objective sits in Describe capabilities of Microsoft Entra, which carries 28% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft Entra

A financial services company wants to require multifactor authentication only when administrators sign in to the Azure portal, without blocking normal user access to other apps. Which Microsoft Entra capability should they configure?

Conditional Access policy targeting administrative roles and the Azure portal applicationCorrect · your answerCorrect: this is exactly the if-then, role-plus-app scoping Conditional Access is designed for.
Microsoft Purview Insider Risk Management policy targeting administrative accountsInsider Risk Management detects risky user activity using logs, it does not enforce sign-in time authentication requirements.
Microsoft Purview Information Barriers policy restricting administrator communicationInformation Barriers restricts communication and collaboration between groups, it has no role in authentication enforcement.
Microsoft Purview Privileged Access Management policy for Exchange configurationPrivileged Access Management provides just-in-time access to sensitive Exchange settings, not MFA enforcement for portal sign-in.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Conditional Access uses if-then statements that combine signals such as user role and target application to enforce access controls like requiring multifactor authentication.

Why A

A Conditional Access policy scoped to administrative roles and the Azure portal app enforces MFA only for that specific sign-in scenario, leaving other access unaffected.

Source

Commonly applied policies Many organizations have common access concerns that Conditional Access policies can help with, such as: Requiring multifactor authentication for users with administrative roles Requiring multifactor authentication for Azure management tasks…

Conditional Access overview, checked July 2026
#conditional-access#zero-trust#entra-id#mfa

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft Entra

What is Conditional Access described as within Microsoft Entra ID?

Sample question 2 of 3

Describe capabilities of Microsoft Entra

An administrator assigns the Contributor role to the Marketing group so its members can manage resources, but only inside the pharma-sales resource group and nowhere else in the subscription. Which element of the role assignment enforces this restriction?

Sample question 3 of 3

Describe capabilities of Microsoft Entra

A user is assigned the Contributor role at the subscription level and the Reader role at a resource group within that subscription. Given how Azure RBAC combines overlapping role assignments, what is the user's effective access on that resource group?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft Entra