Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A security operations center (SOC) analyst observes a significant increase in sign-ins from unfamiliar locations and activities indicating potential credential compromise. The organization uses Microsoft Entra ID. They need a proactive solution that can detect these identity-related risks and automatically take action, such as blocking sign-ins or requiring password resets. Which Microsoft Entra capability should be implemented?
- AMicrosoft Entra Conditional Access
- BMicrosoft Entra Password Protection
- CMicrosoft Entra Access Reviews
- DMicrosoft Entra Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is designed to detect identity-based risks, such as sign-ins from unfamiliar locations or unusual activities. It can be configured to automatically respond to these risks by blocking sign-ins, requiring MFA, or forcing password resets.
Why the other options are wrong
- A. Conditional Access enforces policies based on conditions, but Identity Protection specifically focuses on *detecting and scoring* identity risks.
- B. Password Protection prevents weak passwords but doesn't detect or respond to compromised credentials in real-time.
- C. Access Reviews ensure periodic re-certification of access, not real-time risk detection and response.
Microsoft Entra Identity Protection
A capability that helps organizations detect, investigate, and remediate identity-based risks in Microsoft Entra ID.
- Detects real-time and offline identity anomalies (e.g., unfamiliar locations, impossible travel)
- Calculates user and sign-in risk levels
- Integrates with Conditional Access to automate responses (MFA, block, password reset)
Memory trick: Identity Protection is the risk detective.