Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A security operations center (SOC) analyst observes a significant increase in sign-ins from unfamiliar locations and activities indicating potential credential compromise. The organization uses Microsoft Entra ID. They need a proactive solution that can detect these identity-related risks and automatically take action, such as blocking sign-ins or requiring password resets. Which Microsoft Entra capability should be implemented?

  1. AMicrosoft Entra Conditional Access
  2. BMicrosoft Entra Password Protection
  3. CMicrosoft Entra Access Reviews
  4. DMicrosoft Entra Identity Protection
Show answer & explanation

Correct answer: D. Microsoft Entra Identity Protection

Microsoft Entra Identity Protection is designed to detect identity-based risks, such as sign-ins from unfamiliar locations or unusual activities. It can be configured to automatically respond to these risks by blocking sign-ins, requiring MFA, or forcing password resets.

Why the other options are wrong

  • A. Conditional Access enforces policies based on conditions, but Identity Protection specifically focuses on *detecting and scoring* identity risks.
  • B. Password Protection prevents weak passwords but doesn't detect or respond to compromised credentials in real-time.
  • C. Access Reviews ensure periodic re-certification of access, not real-time risk detection and response.

Microsoft Entra Identity Protection

A capability that helps organizations detect, investigate, and remediate identity-based risks in Microsoft Entra ID.

  • Detects real-time and offline identity anomalies (e.g., unfamiliar locations, impossible travel)
  • Calculates user and sign-in risk levels
  • Integrates with Conditional Access to automate responses (MFA, block, password reset)

Memory trick: Identity Protection is the risk detective.

More Describe the capabilities of Microsoft Entra questions