Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts and existing accounts are prevented from using weak, easily guessable, or previously compromised passwords. They also want to provide specific custom banned password lists. Which Microsoft Entra capability should they implement?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Password Protection
  3. CMicrosoft Entra PIM
  4. DMicrosoft Entra Conditional Access
Show answer & explanation

Correct answer: B. Microsoft Entra Password Protection

Microsoft Entra Password Protection prevents users from creating weak, easily guessable, or compromised passwords by enforcing global and custom banned password lists.

Why the other options are wrong

  • A. Identity Protection detects and remediates identity-based risks like compromised credentials.
  • C. PIM manages just-in-time access for privileged roles.
  • D. Conditional Access enforces policies based on sign-in conditions, not password creation rules.

Microsoft Entra Password Protection

A feature that prevents users from creating weak, easily guessable, or compromised passwords by maintaining global and custom banned password lists.

  • Prevents common and known compromised passwords
  • Allows administrators to define custom banned password lists
  • Works for both cloud-only and hybrid identities

Memory trick: Password Protection bans weak keys.

More Describe the capabilities of Microsoft Entra questions