Objective entra.authenticationSC-900

Describe authentication capabilities of Microsoft Entra ID

Objective entra.authentication sits in Describe capabilities of Microsoft Entra, which carries 28% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft EntraEasy

A compliance officer asks how Microsoft Entra ID Protection builds its risk intelligence for detecting compromised sign-ins. Which set of experience sources feeds this capability?

Correct.

The concept

Microsoft Entra ID Protection derives its threat detection from learnings gathered across Microsoft's own large-scale identity ecosystems, not from a single product's telemetry.

Why this answer

The source states that Microsoft Entra ID Protection uses the learnings Microsoft acquired from organizations using Microsoft Entra ID, the consumer space with Microsoft Accounts, and gaming with Xbox to protect users.

  • AThis describes signal sharing among Defender XDR's own suite products, not the origin of Entra ID Protection's risk intelligence.
  • BOn premises Active Directory signals are the basis for Defender for Identity, a separate identity protection component from Entra ID Protection.
  • CRole assignments and deny assignments belong to Azure RBAC's access evaluation process, unrelated to identity risk detection.
  • Correct: this matches the stated learnings behind Microsoft Entra ID Protection.
Read the sourceMicrosoft Learn: Microsoft Defender XDR
Verified against learn.microsoft.com · 2026-07-28
entra-ididentity-protectionauthenticationdefender-xdr

Now you: objective entra.authentication questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft EntraModerate

A security team wants to detect risky sign-ins and compromised identities using cloud signals drawn from Microsoft Entra ID and consumer account activity, rather than relying on their on-premises Active Directory logs. Which component should they enable?

Sample question 2 of 3

Describe capabilities of Microsoft EntraModerate

A security team wants a cloud-based capability that uses sign-in and risk signal learnings from Microsoft Entra ID, consumer Microsoft Accounts, and Xbox to help protect user identities. Which capability should they use?

Sample question 3 of 3

Describe capabilities of Microsoft EntraModerate

An organisation wants a sign-in method that cannot be replayed by an attacker who intercepts it remotely. Which property of passkeys delivers that?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft Entra