Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard

A security administrator needs to protect all user identities within Azure Active Directory from advanced attacks such as password spray, impossible travel, and malware-linked IP addresses. The solution must also provide automated remediation actions like forcing password resets or blocking sign-ins for risky users. Which Azure AD capability provides this protection?

  1. AAzure AD B2C
  2. BAzure AD Connect
  3. CAzure AD Identity Protection
  4. DAzure AD Conditional Access
Show answer & explanation

Correct answer: C. Azure AD Identity Protection

Azure AD Identity Protection is specifically designed to detect and remediate identity-based risks across Azure AD, including detecting impossible travel, password spray attacks, and sign-ins from malware-infected IP addresses. It also allows for automated remediation policies.

Why the other options are wrong

  • A. Azure AD B2C is for customer-facing applications and managing consumer identities, not internal identity risk detection.
  • B. Azure AD Connect synchronizes identities between on-premises Active Directory and Azure AD, but does not provide risk detection or remediation capabilities.
  • D. Azure AD Conditional Access enforces access policies based on conditions, but Identity Protection is the engine that identifies the 'risk' conditions.

Azure AD Identity Protection

A feature of Azure Active Directory that detects, investigates, and remediates identity-based risks.

  • Detects risky sign-ins and users.
  • Identifies compromised credentials.
  • Automates remediation actions like blocking or MFA enforcement.

Memory trick: Identity Protect: Proactive Risk Patrol.

More Describe the capabilities of Microsoft Security solutions questions