Objective entra.protection-governanceSC-900

Describe identity protection and governance capabilities of Microsoft Entra

Objective entra.protection-governance sits in Describe capabilities of Microsoft Entra, which carries 28% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft EntraModerate

An organization wants new hires to automatically receive user accounts, group memberships, and licenses on their start date, with those assignments removed automatically at termination. Which capability provides this?

Correct.

The concept

Identity products in this family divide by what they do to an account, not by what they know about it. One kind detects that an account is behaving oddly. Another creates, adjusts and removes entitlements on a schedule driven by employment events. A start date and a termination date are lifecycle triggers, and no risk engine acts on them.

Why this answer

Nothing in the scenario mentions suspicious behavior or a decision made at sign-in. Every requirement is tied to an employment event: an account, its group memberships and its licenses appear on a start date and disappear at termination. That join-move-leave automation is identity lifecycle management.

  • Correct: this is the lifecycle automation capability.
  • BID Protection detects and reports identity-based risks, it does not automate account or license lifecycle.
  • CDomain Services provides managed domain services like LDAP and Kerberos for legacy apps, unrelated to lifecycle automation.
  • DWorkload ID manages identities for applications, services, and containers, not employee lifecycle.
  • EVerified ID issues and verifies digital credentials like diplomas, not account provisioning.
Read the sourceWhat is Microsoft Entra ID
Verified against learn.microsoft.com · 2026-07-28
entra-id-governancelifecycle-managementidentity-governance

Now you: objective entra.protection-governance questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft EntraHard

An organization holds only Microsoft Entra ID P1 licenses and wants a Conditional Access policy that requires multifactor authentication whenever the calculated sign-in risk is medium or high. What must the organization do?

Sample question 2 of 3

Describe capabilities of Microsoft EntraModerate

An administrator wants new hires to automatically receive the correct group memberships and licenses, and have those removed when they leave the company. Which Microsoft Entra capability provides this automation?

Sample question 3 of 3

Describe capabilities of Microsoft EntraHard

A security team wants Conditional Access to require multifactor authentication only when a user's sign-in risk is calculated as medium or high. Which capability and license tier must be enabled to support this policy?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft Entra