Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy
A company is implementing Microsoft Entra ID. They want to ensure that users are prompted for an additional verification method when signing in from an unfamiliar location or a non-compliant device. Which Microsoft Entra capability should they configure?
- AMicrosoft Entra Privileged Identity Management
- BMicrosoft Entra Connect
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra Domain Services
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is designed to detect and respond to identity-based risks, such as sign-ins from unfamiliar locations or compromised devices, by enforcing policies like multi-factor authentication.
Why the other options are wrong
- A. This service manages, controls, and monitors access to important resources, but doesn't primarily focus on risk-based sign-in prompts.
- B. This tool synchronizes on-premises directories with Microsoft Entra ID, not for risk-based access control.
- D. This service provides managed domain services for virtual machines, not for identity risk detection.
Microsoft Entra Identity Protection
A feature of Microsoft Entra ID that detects potential identity-based risks, such as compromised credentials or suspicious sign-ins, and can automatically respond to these risks.
- Detects risk events like anomalous sign-ins, leaked credentials, and malware.
- Enforces policies like multi-factor authentication or password resets based on risk level.
- Provides reports on risky users and sign-ins.
Memory trick: Entra's got your back, protecting identities from every crack.