SC-900 - Microsoft Entra Capabilities (27% of the exam) - Section 2.1

Describe the function and identity types of Microsoft Entra ID.

Describe Microsoft Entra ID as a cloud-based identity service and distinguish the types of identities it manages, including users, service principals, and managed identities. Recognise how hybrid identity connects on-premises Active Directory with Microsoft Entra ID to provide a unified directory.

Microsoft Entra IDtypes of identitieshybrid identity

Practice question for this objective

Free sampleMicrosoft Entra Capabilitieseasy

An architect is listing the identity types that Microsoft Entra ID can represent for machine or non-human workloads, as opposed to human users. Which TWO of the following are machine identity types in Microsoft Entra ID? Select TWO.

  • AA guest user account invited from a partner organisation to collaborate
  • BA service principal that represents an application instance within the tenant Correct
  • CA member user account created directly inside the organisation's own directory
  • DA managed identity assigned to an Azure resource so it can reach other services Correct
  • EA security group used to grant several users access to a shared application
Microsoft Entra ID represents machine or non-human workloads through service principals and managed identities, distinct from human user accounts. Service principals and managed identities are the non-human identity types: applications authenticate through service principals, and Azure resources use managed identities to remove stored secrets. Member and guest accounts are human identities, and a group is an access container, not an authenticating identity.

Why A is wrong: A guest is a real Entra identity, but it represents a human collaborator, so it is not a machine or non-human identity type.

Why B is correct: A service principal is the local identity an application uses to authenticate and be authorised, a core machine identity type.

Why C is wrong: A member user is a human identity native to the tenant, so it does not belong to the machine or non-human category.

Why D is correct: A managed identity gives an Azure resource an automatically managed identity in Entra, a machine identity that removes credential handling.

Why E is wrong: A group bundles users for access management but is not itself an identity that authenticates, so it is not a machine identity.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Entra Capabilities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • It is a managed domain service that provides group policy, LDAP, and Kerberos for legacy applications.

    Why it is wrong: Group policy, LDAP, and Kerberos for legacy apps describe Microsoft Entra Domain Services, a separate product in the family, not Microsoft Entra ID itself.

  • It provides managed domain services such as Kerberos and legacy LDAP without on-premises controllers

    Why it is wrong: Managed domain services with Kerberos and LDAP describe Microsoft Entra Domain Services, a separate product, not Entra ID itself.

  • Lifecycle workflows, which run automated tasks at key events such as a user joining, moving, or leaving.

    Why it is wrong: Lifecycle workflows automate tasks tied to key employment events such as sending a temporary access pass; they do not retrieve HR records to create and maintain the underlying user identities.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.