Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A company is concerned about insider threats and compromised user accounts. They need a solution that can detect suspicious user behavior, such as impossible travel, sign-ins from unfamiliar locations, and brute-force attacks, and automatically respond to these risks. Which Azure Active Directory capability should they leverage?
- AAzure AD Domain Services
- BAzure AD B2C
- CAzure AD Connect
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Identity Protection
Azure AD Identity Protection is a feature of Azure Active Directory that helps organizations detect, investigate, and remediate identity-based risks, including suspicious user behavior like impossible travel and sign-ins from unfamiliar locations, providing automated responses.
Why the other options are wrong
- A. Azure AD Domain Services provides managed domain services for cloud-based applications and VMs.
- B. Azure AD B2C is a customer identity access management (CIAM) service for consumer-facing applications.
- C. Azure AD Connect synchronizes on-premises directories with Azure AD, not for risk detection.
Azure AD Identity Protection
A feature of Azure Active Directory that detects identity-based risks, including compromised credentials, suspicious sign-ins, and risky users. It provides risk reports and automated responses like blocking access or enforcing multi-factor authentication.
- Detects identity-based risks (e.g., impossible travel).
- Provides risk scores for users and sign-ins.
- Offers automated remediation actions.
Memory trick: Identity Protection guards users from risky behavior.