Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A security administrator needs to protect all user identities within Azure Active Directory from advanced attacks such as password spray, impossible travel, and malware-linked IP addresses. The solution must also provide automated remediation actions like forcing password resets or blocking sign-ins for risky users. Which Azure AD capability provides this protection?
- AAzure AD B2C
- BAzure AD Connect
- CAzure AD Identity Protection
- DAzure AD Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Identity Protection
Azure AD Identity Protection is specifically designed to detect and remediate identity-based risks across Azure AD, including detecting impossible travel, password spray attacks, and sign-ins from malware-infected IP addresses. It also allows for automated remediation policies.
Why the other options are wrong
- A. Azure AD B2C is for customer-facing applications and managing consumer identities, not internal identity risk detection.
- B. Azure AD Connect synchronizes identities between on-premises Active Directory and Azure AD, but does not provide risk detection or remediation capabilities.
- D. Azure AD Conditional Access enforces access policies based on conditions, but Identity Protection is the engine that identifies the 'risk' conditions.
Azure AD Identity Protection
A feature of Azure Active Directory that detects, investigates, and remediates identity-based risks.
- Detects risky sign-ins and users.
- Identifies compromised credentials.
- Automates remediation actions like blocking or MFA enforcement.
Memory trick: Identity Protect: Proactive Risk Patrol.