Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A security administrator is reviewing user sign-in logs in Azure AD and notices several failed sign-in attempts for a specific user account originating from unusual geographic locations. The administrator suspects a potential brute-force attack or credential compromise. Which Azure AD feature provides automated protection against such threats by analyzing sign-in behavior and applying remediation actions?

  1. AAccess Reviews
  2. BCustom security attributes
  3. CIdentity Protection
  4. DPIM (Privileged Identity Management)
Show answer & explanation

Correct answer: C. Identity Protection

Azure AD Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses machine learning to analyze sign-in behavior and user activity, identifying suspicious actions like sign-ins from unfamiliar locations or impossible travel, and can automatically block or require MFA for risky sign-ins.

Why the other options are wrong

  • A. Access Reviews help manage group memberships and application access periodically, not for automated sign-in risk assessment.
  • B. Custom security attributes are used to categorize and secure directory objects, not for real-time sign-in risk detection.
  • D. PIM focuses on managing, controlling, and monitoring access to important resources, not automated threat detection for sign-ins.

Azure AD Identity Protection

An Azure AD Premium P2 feature that detects, investigates, and remediates identity-based risks by analyzing sign-in and user behavior.

  • Detects sign-in risks (e.g., impossible travel, unfamiliar locations).
  • Detects user risks (e.g., leaked credentials).
  • Can automatically enforce remediation actions like MFA or blocking.

Memory trick: Protect Identities, Prevent Intrusions.

More Implement an authentication and access management solution questions