Exam objective
SC-900Describe authentication capabilities of Microsoft Entra ID
This objective sits in Describe capabilities of Microsoft Entra, which carries 28% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An organization wants to stop users choosing passwords that contain its product names and office locations. Which Microsoft Entra capability does this?
Correct.
Checked against learn.microsoft.com, September 2026Concept
A vendor can only know which passwords are weak everywhere; the words that are weak inside one company are something only that company can supply.
Why D
The source says default global banned password lists apply to all users automatically, and that to support your own business and security needs you can define entries in a custom banned password list, checked when users change or reset passwords.
Source
Describe password protection and management capabilities, checked September 2026With Microsoft Entra password protection, default global banned password lists are automatically applied to all users in a Microsoft Entra tenant. To support your own business and security needs, you can define entries in a custom banned password list. When users change or reset their passwords, these lists are checked to enforce the use of strong passwords.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A new employee has no authentication methods registered. An administrator wants to issue a time-limited code the employee can use to sign in and register a passkey. Which method fits?
Sample question 2 of 3
A help desk spends much of each Monday unlocking accounts and resetting forgotten passwords. Which Microsoft Entra feature lets users fix this themselves?
Sample question 3 of 3
An organization wants a sign-in method that cannot be replayed by an attacker who intercepts it remotely. Which property of passkeys delivers that?
Full Security, Compliance, and Identity Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.