SC-900 - Microsoft Entra Capabilities (27% of the exam) - Section 2.3

Describe the access management capabilities of Microsoft Entra ID.

Describe how Conditional Access policies enforce access decisions based on signals such as user, device, and location. Distinguish Microsoft Entra roles from resource-level role-based access control, and choose the appropriate model for delegating permissions to administrators or to application resources.

Conditional AccessMicrosoft Entra rolesrole-based access control

Practice question for this objective

Free sampleMicrosoft Entra Capabilitiesmedium

An administrator must grant a user the ability to manage users and groups in the directory, but not to manage any virtual machines. Which role-based access control system controls access to those directory resources?

  • AAzure roles, which control access to Azure resources such as virtual machines through Azure Resource Manager.
  • BMicrosoft Entra roles, which control access to directory resources through Microsoft Graph. Correct
  • CNetwork security groups, which control inbound and outbound traffic to Azure resources.
  • DConditional Access policies, which control the conditions under which a sign-in is allowed.
Microsoft Entra roles control directory resources via Microsoft Graph, while Azure roles control Azure resources via Azure Resource Manager. The grounding states Microsoft Entra roles control access to Microsoft Entra resources such as users, groups, and applications using the Microsoft Graph API, whereas Azure roles control access to Azure resources such as virtual machines using Azure Resource Management.

Why A is wrong: Azure roles control Azure resources such as virtual machines through Azure Resource Manager, not directory resources such as users and groups.

Why B is correct: Correct. The grounding states Microsoft Entra roles control access to Microsoft Entra resources such as users, groups, and applications using the Microsoft Graph API, whereas Azure roles control access to Azure resources such as virtual machines using Azure Resource Management.

Why C is wrong: Network security groups filter network traffic to Azure resources and do not grant administrative permissions over directory users and groups.

Why D is wrong: Conditional Access governs the conditions of a sign-in, not which administrative permissions a user holds over directory users and groups.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Entra Capabilities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Microsoft Entra ID Protection, which detects and remediates identity-based sign-in risks.

    Why it is wrong: ID Protection detects and remediates identity risk such as leaked credentials; it does not manage, control, and monitor access to privileged resources.

  • The user's job title as recorded in their Microsoft Entra ID profile

    Why it is wrong: Tempting because policies are assigned to users and groups, but a free-text directory attribute such as job title is not one of the conditions the Conditional Access engine evaluates.

  • Azure RBAC controls who may approve a risky sign-in detected by ID Protection

    Why it is wrong: Approving or remediating risky sign-ins is handled in ID Protection and Conditional Access, not by Azure resource RBAC assignments.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.