Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A security administrator needs to protect all user identities within Azure Active Directory from compromise, including detecting suspicious sign-ins, risky user behavior, and providing automated remediation actions like blocking access or requiring multi-factor authentication (MFA). Which Azure security solution should be configured?
- AAzure AD Identity Protection
- BMicrosoft Defender for Endpoint
- CAzure AD Conditional Access
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Identity Protection
Azure AD Identity Protection is specifically designed to detect, investigate, and remediate identity-based risks in Azure AD, including suspicious sign-ins and risky users, and can trigger automated remediation actions through Conditional Access.
Why the other options are wrong
- B. Microsoft Defender for Endpoint protects devices, not user identities in Azure AD.
- C. Azure AD Conditional Access enforces policies based on conditions but relies on Identity Protection to feed it risk signals for automated remediation based on risk.
- D. Azure Firewall protects network traffic, not user identities.
Azure AD Identity Protection
A feature of Azure Active Directory that detects potential identity-based risks, such as compromised credentials, suspicious sign-ins, and risky users, and enables automated remediation actions.
- Detects identity-based risks
- Identifies risky users and sign-ins
- Integrates with Conditional Access for automated remediation
Memory trick: Identity Protection guards your user accounts from risky moves.