Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A security operations center (SOC) analyst observes a significant increase in sign-ins from unusual locations and impossible travel scenarios within Microsoft Entra ID. They need a capability that can detect these suspicious activities automatically and apply real-time remediation actions, such as blocking the sign-in or forcing a password change. Which Microsoft Entra capability provides this advanced threat detection and automated response?
- AMicrosoft Entra Conditional Access
- BMicrosoft Entra Identity Protection
- CMicrosoft Entra Access Reviews
- DMicrosoft Entra PIM
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is designed to detect identity-based risks, such as impossible travel or sign-ins from unfamiliar locations, and can be configured to automatically apply real-time remediation actions like blocking access or requiring password changes based on detected risk levels.
Why the other options are wrong
- A. Conditional Access enforces policies based on static conditions but does not dynamically detect impossible travel or automatically apply risk-based remediation actions.
- C. Access Reviews focus on periodic verification of access rights, not real-time threat detection and response.
- D. PIM manages just-in-time access for privileged roles; it does not perform real-time risk detection for all user sign-ins.
Microsoft Entra Identity Protection
A feature of Microsoft Entra ID that helps detect, investigate, and remediate identity-based risks by monitoring user and sign-in behavior for anomalies.
- Detects identity-based risks (e.g., impossible travel, leaked credentials).
- Calculates real-time risk scores for users and sign-ins.
- Automates remediation actions based on defined policies.
Memory trick: Identity Protection is the watchful AI bodyguard for your users.