Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy

A global consulting firm uses Microsoft Entra ID and has a policy requiring that all users, especially those in administrative roles, confirm their identity using at least two different authentication factors before accessing sensitive corporate resources. Which Microsoft Entra capability should be configured to enforce this policy?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Password Protection
  3. CMicrosoft Entra Privileged Identity Management (PIM)
  4. DMicrosoft Entra multifactor authentication (MFA)
Show answer & explanation

Correct answer: D. Microsoft Entra multifactor authentication (MFA)

Multifactor authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, directly enforcing the policy of using at least two different authentication factors.

Why the other options are wrong

  • A. Microsoft Entra Identity Protection detects and remediates risks, it does not directly enforce the use of multiple authentication factors.
  • B. Microsoft Entra Password Protection prevents the use of weak or compromised passwords, not enforcing multiple factors.
  • C. Microsoft Entra PIM manages elevated access to privileged roles, but MFA is the mechanism to enforce multi-factor identity confirmation.

Multifactor Authentication (MFA)

An authentication method that requires the user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.

  • Adds an extra layer of security beyond just a password
  • Common factors include something you know (password), something you have (phone), something you are (fingerprint)
  • Significantly reduces the risk of credential compromise

Memory trick: More factors mean more fortress.

More Describe the capabilities of Microsoft Entra questions