Exam objective
SC-900Describe identity protection and governance capabilities of Microsoft Entra
This objective sits in Describe capabilities of Microsoft Entra, which carries 28% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A security team wants a cloud-based capability that uses sign-in and risk signal learnings from Microsoft Entra ID, consumer Microsoft Accounts, and Xbox to help protect user identities. Which capability should they use?
Correct.
Checked against learn.microsoft.com, July 2026Concept
The distinguishing detail here is the training population, not the word identity in a product name. A service that learns from workforce directories, consumer accounts and a gaming platform is drawing on internet-scale sign-in telemetry. One anchored to domain controller traffic sees a single organization, and an authorization system does not observe sign-in behavior at all.
Why B
Only one of these services is trained on all three named populations: workforce accounts in Microsoft Entra ID, consumer Microsoft Accounts, and Xbox. That breadth is what lets Microsoft Entra ID Protection score a sign-in it has never seen before as risky.
Source
Microsoft Learn: Microsoft Defender XDR, checked July 2026Microsoft Entra ID Protection uses the learnings Microsoft acquired from their position in organizations with Microsoft Entra ID, the consumer space with Microsoft Accounts, and in gaming with Xbox to protect your users.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An organization wants new hires to automatically receive user accounts, group memberships, and licenses on their start date, with those assignments removed automatically at termination. Which capability provides this?
Sample question 2 of 3
In Privileged Identity Management, an administrator gives one user an eligible assignment to a role and another an active assignment to the same role. What is the difference for the users?
Sample question 3 of 3
A security administrator builds a Conditional Access policy that requires multifactor authentication only when a sign-in is scored as medium or high risk. Which capability supplies this risk signal to the policy?
Full Security, Compliance, and Identity Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.