Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A security administrator needs to protect all user identities within Azure Active Directory (Azure AD) from compromised credentials, brute-force attacks, and suspicious sign-in activities. They want to set up policies that automatically block or challenge users based on risk levels. Which Microsoft security solution provides these capabilities?

  1. AMicrosoft Defender for Endpoint
  2. BMicrosoft Defender for Cloud Apps
  3. CAzure AD Identity Protection
  4. DMicrosoft Intune
Show answer & explanation

Correct answer: C. Azure AD Identity Protection

Azure AD Identity Protection is specifically designed to detect and remediate identity-based risks in Azure AD. It identifies vulnerabilities, detects suspicious sign-in activities and compromised identities, and can apply automated policies like requiring MFA or blocking access.

Why the other options are wrong

  • A. Microsoft Defender for Endpoint protects devices from malware and exploits, not identity-specific risks in Azure AD.
  • B. Microsoft Defender for Cloud Apps focuses on cloud application usage and data security, not Azure AD identity risk detection.
  • D. Microsoft Intune manages and secures endpoints and mobile devices, not identity risk within Azure AD.

Azure AD Identity Protection

A feature of Azure Active Directory that detects and remediates identity-based risks, including compromised credentials and suspicious sign-in behaviors.

  • Identifies vulnerable user accounts and risky sign-ins
  • Calculates a real-time risk score for users and sign-ins
  • Enables automated response policies (e.g., MFA, block access)

Memory trick: Identity Protection guards your digital self.

More Describe the capabilities of Microsoft Security solutions questions