SC-900 - Microsoft Entra Capabilities - Section 2.2

Describe the authentication capabilities of Microsoft Entra ID.

Compare authentication methods available in Microsoft Entra ID, including passwords, FIDO2 keys, and OATH tokens, and explain how multifactor authentication reduces the risk of credential compromise. Describe how password protection and self-service password reset improve security while reducing helpdesk load.

authentication methodsmultifactor authenticationpassword protection and management

Practice question for this objective

Free sampleMicrosoft Entra Capabilitiesmedium

An administrator is enabling self-service password reset and password protection in Microsoft Entra ID and wants to confirm what each capability actually does. Which THREE statements about these capabilities are correct? Select THREE.

  • ASelf-service password reset lets users change or reset their own passwords without help desk contact Correct
  • BPassword protection blocks weak passwords by checking them against banned password lists Correct
  • CSelf-service password reset requires users to register approved authentication methods beforehand Correct
  • DPassword protection applies only to cloud accounts and cannot be extended to on-premises Active Directory
  • EPassword protection responds to a weak password by automatically enrolling the user in multifactor authentication
Self-service password reset lets users reset their own passwords after registering methods, while password protection enforces banned password lists. Self-service password reset reduces help desk load by letting verified users reset their own passwords, and it requires prior registration of authentication methods, so A and C are correct. Password protection separately enforces global and custom banned password lists, so B is correct. Password protection can be extended to on-premises Active Directory using domain controller agents, and it never enrols users in multifactor authentication, so D and E are wrong.

Why A is correct: Self-service password reset allows users to reset or unlock their accounts themselves after verifying identity, which is its purpose.

Why B is correct: Password protection evaluates new passwords against the global and custom banned lists to stop weak choices, which is correct.

Why C is correct: Users must register the required number of authentication methods before they can verify identity and use self-service reset.

Why D is wrong: Tempting because the feature lives in Microsoft Entra, but password protection can be extended to on-premises Active Directory using domain controller agents, so the cloud-only claim is wrong.

Why E is wrong: Tempting because both harden sign-in, but password protection only screens passwords against banned lists; enrolling a user in multifactor authentication is a separate capability it never performs.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Entra Capabilities objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.