Exam objective

SC-900

Describe identity protection and governance capabilities of Microsoft Entra

This objective sits in Describe capabilities of Microsoft Entra, which carries 28% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft Entra

A security team wants a cloud-based capability that uses sign-in and risk signal learnings from Microsoft Entra ID, consumer Microsoft Accounts, and Xbox to help protect user identities. Which capability should they use?

Azure role-based access control authorization serviceAzure RBAC decides what an authenticated principal may do. It has no view of how risky the sign-in was.
Microsoft Entra ID Protection identity risk serviceCorrect · your answerCorrect: this is the capability built on Entra ID, Microsoft Account, and Xbox sign-in learnings.
Microsoft Defender for Cloud Apps SaaS security serviceMicrosoft Defender for Cloud Apps sees what happens inside SaaS sessions after sign-in, not the sign-in itself.
Microsoft Defender for Identity on-premises AD serviceMicrosoft Defender for Identity would be the answer if the telemetry came from domain controllers in an on-premises forest.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

The distinguishing detail here is the training population, not the word identity in a product name. A service that learns from workforce directories, consumer accounts and a gaming platform is drawing on internet-scale sign-in telemetry. One anchored to domain controller traffic sees a single organization, and an authorization system does not observe sign-in behavior at all.

Why B

Only one of these services is trained on all three named populations: workforce accounts in Microsoft Entra ID, consumer Microsoft Accounts, and Xbox. That breadth is what lets Microsoft Entra ID Protection score a sign-in it has never seen before as risky.

Source

Microsoft Entra ID Protection uses the learnings Microsoft acquired from their position in organizations with Microsoft Entra ID, the consumer space with Microsoft Accounts, and in gaming with Xbox to protect your users.

Microsoft Learn: Microsoft Defender XDR, checked July 2026
#entra-id#authentication#identity-protection#defender-xdr

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft Entra

An organization wants new hires to automatically receive user accounts, group memberships, and licenses on their start date, with those assignments removed automatically at termination. Which capability provides this?

Sample question 2 of 3

Describe capabilities of Microsoft Entra

In Privileged Identity Management, an administrator gives one user an eligible assignment to a role and another an active assignment to the same role. What is the difference for the users?

Sample question 3 of 3

Describe capabilities of Microsoft Entra

A security administrator builds a Conditional Access policy that requires multifactor authentication only when a sign-in is scored as medium or high risk. Which capability supplies this risk signal to the policy?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft Entra