Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A security team observes unusual sign-in patterns, such as sign-ins from unfamiliar locations or multiple failed sign-in attempts from the same account. They need a Microsoft Entra capability to automatically detect these suspicious activities and, optionally, trigger actions like requiring multifactor authentication or blocking the sign-in. Which Microsoft Entra capability provides this automated risk detection and response?

  1. AMicrosoft Entra Password Protection
  2. BMicrosoft Entra Identity Protection
  3. CMicrosoft Entra Multifactor Authentication (MFA)
  4. DMicrosoft Entra Conditional Access
Show answer & explanation

Correct answer: B. Microsoft Entra Identity Protection

Microsoft Entra Identity Protection is specifically designed to detect, investigate, and remediate identity-based risks. It identifies suspicious user and sign-in behaviors and can automate responses based on these risk detections.

Why the other options are wrong

  • A. Password Protection prevents weak passwords, not detects suspicious sign-in activities.
  • C. MFA is an authentication method, not a risk detection and response system.
  • D. Conditional Access enforces policies based on static conditions or risk levels provided by Identity Protection, but doesn't *detect* the risk itself.

Microsoft Entra Identity Protection

A security module of Microsoft Entra ID that detects, investigates, and remediates identity-based risks.

  • Identifies anomalous user behavior and risky sign-ins.
  • Calculates user risk and sign-in risk levels.
  • Can trigger automated remediation actions (e.g., block, MFA).

Memory trick: Identity Protection is your personal security guard for user accounts, always watching for trouble.

More Describe the capabilities of Microsoft Entra questions