Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
A small business uses Azure Active Directory (Azure AD) as its primary identity provider. They are concerned about account compromise due to weak passwords, brute-force attacks, and suspicious sign-in attempts from unusual locations. They need a solution that can automatically detect these identity-based risks and enforce adaptive policies like multi-factor authentication (MFA) or password resets to protect user accounts. Which Azure security service provides these capabilities?
- AAzure Active Directory Identity Protection
- BMicrosoft Defender for Identity
- CAzure Security Center
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Active Directory Identity Protection
Azure Active Directory Identity Protection is a feature within Azure AD that enables organizations to detect, investigate, and remediate identity-based risks, such as suspicious sign-ins, compromised credentials, and anomalous user behavior, often by enforcing Conditional Access policies like MFA.
Why the other options are wrong
- B. Microsoft Defender for Identity protects on-premises Active Directory identities, not primarily cloud-based Azure AD sign-in risks.
- C. Azure Security Center (now Defender for Cloud) focuses on cloud security posture management and workload protection, not identity risk detection within Azure AD.
- D. Azure Firewall provides network traffic filtering, completely unrelated to identity protection.
Azure Active Directory Identity Protection
A feature of Azure AD that detects identity-based risks, such as compromised accounts and suspicious sign-ins.
- Detects real-time and offline identity risks.
- Integrates with Conditional Access policies.
- Provides risk-based remediation actions (MFA, password reset, block).
Memory trick: Azure AD IP is the 'bouncer' for your cloud identities, stopping suspicious sign-ins.