AB-900 - Identify the core features and objects of Microsoft 365 services - Section 1.3

Identify the core security features of Microsoft 365 services and the tool that addresses a given problem.

Microsoft Entra ID capabilities, conditional access policies, single sign-on, choosing between users and groups as the security object, troubleshooting sign-in issues (MFA, conditional access, risky sign-ins), interpreting Identity Secure Score, reviewing audit logs, the role of Privileged Identity Management, and App registrations versus Enterprise apps. Revised in the 22 July 2026 outline update.

Microsoft Entra IDconditional access policiessingle sign-on (SSO)multifactor authentication (MFA)risky sign-insIdentity Secure ScorePrivileged Identity Management (PIM)App registrations versus Enterprise apps

Practice question for this objective

Free sampleIdentify the core features and objects of Microsoft 365 servicesmedium

A security team wants each global administrator to hold their elevated role only for the short period they actively need it, with an approval and an audit trail every time the role is switched on, rather than being permanently assigned. Which Microsoft Entra ID capability meets this requirement?

  • AIdentity Secure Score, which grades the tenant and grants the role temporarily once the score threshold is met
  • BA conditional access policy that grants the administrator role for a limited session after multifactor authentication
  • CSingle sign-on, which issues the administrator role automatically when the user authenticates once
  • DPrivileged Identity Management, which makes the role eligible and requires just-in-time activation with approval and auditing Correct
Identify Privileged Identity Management as the Microsoft Entra ID capability that provides just-in-time, approved, audited privileged role activation. Privileged Identity Management reduces standing access by making privileged roles eligible rather than permanently active, so administrators activate them only when needed, subject to approval, time limits and logging.

Why A is wrong: Identity Secure Score reports on security posture and recommends improvements, but it does not assign, time-box, or approve administrative roles.

Why B is wrong: Conditional access can require multifactor authentication before access, but it does not assign directory roles or provide just-in-time role activation with approvals.

Why C is wrong: Single sign-on streamlines authentication across applications and has no ability to grant, time-box, or approve privileged role activation.

Why D is correct: Privileged Identity Management provides eligible assignments, time-bound just-in-time activation, optional approval, and an audit trail, which is precisely the described need.

See more AB-900 practice questions, answers explained.

More in this domain

Back to all Identify the core features and objects of Microsoft 365 services objectives, or the AB-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.