SC-900 - Microsoft Entra Capabilities - Section 2.1

Describe the function and identity types of Microsoft Entra ID.

Describe Microsoft Entra ID as a cloud-based identity service and distinguish the types of identities it manages, including users, service principals, and managed identities. Recognise how hybrid identity connects on-premises Active Directory with Microsoft Entra ID to provide a unified directory.

Microsoft Entra IDtypes of identitieshybrid identity

Practice question for this objective

Free sampleMicrosoft Entra Capabilitieseasy

An architect is listing the identity types that Microsoft Entra ID can represent for machine or non-human workloads, as opposed to human users. Which TWO of the following are machine identity types in Microsoft Entra ID? Select TWO.

  • AA guest user account invited from a partner organisation to collaborate
  • BA service principal that represents an application instance within the tenant Correct
  • CA member user account created directly inside the organisation's own directory
  • DA managed identity assigned to an Azure resource so it can reach other services Correct
  • EA security group used to grant several users access to a shared application
Microsoft Entra ID represents machine or non-human workloads through service principals and managed identities, distinct from human user accounts. Service principals and managed identities are the non-human identity types: applications authenticate through service principals, and Azure resources use managed identities to remove stored secrets. Member and guest accounts are human identities, and a group is an access container, not an authenticating identity.

Why A is wrong: A guest is a real Entra identity, but it represents a human collaborator, so it is not a machine or non-human identity type.

Why B is correct: A service principal is the local identity an application uses to authenticate and be authorised, a core machine identity type.

Why C is wrong: A member user is a human identity native to the tenant, so it does not belong to the machine or non-human category.

Why D is correct: A managed identity gives an Azure resource an automatically managed identity in Entra, a machine identity that removes credential handling.

Why E is wrong: A group bundles users for access management but is not itself an identity that authenticates, so it is not a machine identity.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Entra Capabilities objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.