Describe identity protection and governance capabilities of Microsoft Entra
Objective entra.protection-governance sits in Describe capabilities of Microsoft Entra, which carries 28% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An organization wants new hires to automatically receive user accounts, group memberships, and licenses on their start date, with those assignments removed automatically at termination. Which capability provides this?
The concept
Identity products in this family divide by what they do to an account, not by what they know about it. One kind detects that an account is behaving oddly. Another creates, adjusts and removes entitlements on a schedule driven by employment events. A start date and a termination date are lifecycle triggers, and no risk engine acts on them.
Why this answer
Nothing in the scenario mentions suspicious behavior or a decision made at sign-in. Every requirement is tied to an employment event: an account, its group memberships and its licenses appear on a start date and disappear at termination. That join-move-leave automation is identity lifecycle management.
- Correct: this is the lifecycle automation capability.
- BID Protection detects and reports identity-based risks, it does not automate account or license lifecycle.
- CDomain Services provides managed domain services like LDAP and Kerberos for legacy apps, unrelated to lifecycle automation.
- DWorkload ID manages identities for applications, services, and containers, not employee lifecycle.
- EVerified ID issues and verifies digital credentials like diplomas, not account provisioning.
Now you: objective entra.protection-governance questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An organization holds only Microsoft Entra ID P1 licenses and wants a Conditional Access policy that requires multifactor authentication whenever the calculated sign-in risk is medium or high. What must the organization do?
Sample question 2 of 3
An administrator wants new hires to automatically receive the correct group memberships and licenses, and have those removed when they leave the company. Which Microsoft Entra capability provides this automation?
Sample question 3 of 3
A security team wants Conditional Access to require multifactor authentication only when a user's sign-in risk is calculated as medium or high. Which capability and license tier must be enabled to support this policy?
Full SCI Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.