Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A manufacturing company needs to manage identity-related risks within Microsoft Entra ID. They want to automatically detect suspicious actions, such as impossible travel, sign-ins from unfamiliar locations, or leaked credentials, and configure automated responses like blocking access or requiring multifactor authentication (MFA). Which Microsoft Entra capability provides these automated detection and response features?
- AMicrosoft Entra Identity Protection
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Access Reviews
- DMicrosoft Entra Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is specifically designed to detect identity-based risks (like impossible travel, unfamiliar sign-in locations, leaked credentials) and enables administrators to configure automated remediation actions, such as blocking access or enforcing MFA.
Why the other options are wrong
- B. PIM manages just-in-time access for privileged roles, not general risk detection.
- C. Access Reviews manage periodic access validation, not real-time risk detection.
- D. Conditional Access enforces policies based on conditions, but Identity Protection is the engine that feeds risk signals into it.
Microsoft Entra Identity Protection
A security feature that detects identity-based risks, such as suspicious sign-ins or compromised credentials, and automates remediation actions to protect user identities.
- Detects real-time and offline identity risks (impossible travel, unfamiliar locations, leaked credentials)
- Integrates with Conditional Access to enforce automated responses (block access, require MFA)
- Provides risk reports and investigations for administrators
Memory trick: Identity Protection automatically guards against risky identity moves.