Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A security team observes unusual sign-in patterns, such as sign-ins from unfamiliar locations or multiple failed sign-in attempts from the same account. They need a Microsoft Entra capability to automatically detect these suspicious activities and, optionally, trigger actions like requiring multifactor authentication or blocking the sign-in. Which Microsoft Entra capability provides this automated risk detection and response?
- AMicrosoft Entra Password Protection
- BMicrosoft Entra Identity Protection
- CMicrosoft Entra Multifactor Authentication (MFA)
- DMicrosoft Entra Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is specifically designed to detect, investigate, and remediate identity-based risks. It identifies suspicious user and sign-in behaviors and can automate responses based on these risk detections.
Why the other options are wrong
- A. Password Protection prevents weak passwords, not detects suspicious sign-in activities.
- C. MFA is an authentication method, not a risk detection and response system.
- D. Conditional Access enforces policies based on static conditions or risk levels provided by Identity Protection, but doesn't *detect* the risk itself.
Microsoft Entra Identity Protection
A security module of Microsoft Entra ID that detects, investigates, and remediates identity-based risks.
- Identifies anomalous user behavior and risky sign-ins.
- Calculates user risk and sign-in risk levels.
- Can trigger automated remediation actions (e.g., block, MFA).
Memory trick: Identity Protection is your personal security guard for user accounts, always watching for trouble.