Objective identity.conceptsSC-900

Define identity concepts

Objective identity.concepts sits in Describe concepts of security, compliance, and identity, which carries 12% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe concepts of security, compliance, and identityModerate

A finance company requires every admin to complete multifactor authentication before reaching the Azure portal, but only after their username and password are verified. Which statement describes when this Conditional Access enforcement actually occurs?

Correct.

The concept

Conditional Access is a Zero Trust policy engine that evaluates identity-driven signals and enforces if-then access decisions, but only after the user's initial credentials are validated.

Why this answer

Conditional Access policies are explicitly enforced after first-factor authentication is completed, so requiring MFA at the Azure portal fits this sequencing exactly.

  • Correct: this matches the documented enforcement order for Conditional Access.
  • BConditional Access adds a second layer of controls on top of first-factor authentication, it does not replace it.
  • CThe source explicitly states Conditional Access is not intended as an organization's frontline defense against denial-of-service attacks.
  • DConditional Access can trigger policies for on-premises apps, agent resources, and traditional cloud apps alike, not just one category.
  • EHybrid join can be a grant control requirement, but access is not granted automatically without evaluating the full policy.
Read the sourceMicrosoft Entra Conditional Access overview
Verified against learn.microsoft.com · 2026-07-28
conditional-accessauthenticationidentity-signals

Now you: objective identity.concepts questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe concepts of security, compliance, and identityHard

An organization removes standing administrator access to Exchange configuration settings. Admins must now request temporary elevated access only when performing a specific task. Which Zero Trust guiding principle does this practice best reflect?

Sample question 2 of 3

Describe concepts of security, compliance, and identityModerate

An admin configures a Conditional Access policy so that users can reach a finance application only from devices marked compliant, with no other requirement added. Which decision type does this policy represent?

Sample question 3 of 3

Describe concepts of security, compliance, and identityHard

A company already has Microsoft Entra ID P1 and wants a Conditional Access policy that blocks sign-ins flagged by real-time risk detection. Which action completes this configuration?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe concepts of security, compliance, and identity