Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium
A Microsoft 365 administrator is reviewing the organization's security posture and wants to determine if any user accounts have been compromised or are exhibiting risky behavior, such as sign-ins from unusual locations or attempts to access disabled accounts. The administrator needs a centralized view of these potential identity risks. Which Microsoft 365 capability provides this insight?
- AAzure AD Identity Protection
- BAzure AD Conditional Access
- CMicrosoft 365 Defender portal
- DMicrosoft Purview Compliance Manager
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Identity Protection
Azure AD Identity Protection is specifically designed to detect, investigate, and remediate identity-based risks. It identifies vulnerabilities like weak passwords, and detects suspicious user and sign-in activities, providing a centralized view of identity risks.
Why the other options are wrong
- B. Conditional Access enforces policies based on conditions, but Identity Protection is the engine that identifies the 'risky behavior' in the first place.
- C. The Microsoft 365 Defender portal focuses on endpoint, email, and cloud app security, not specifically identity risk detection.
- D. Compliance Manager helps manage compliance posture against regulations, not active identity risk detection.
Azure AD Identity Protection
A feature of Azure Active Directory that helps organizations detect, investigate, and remediate identity-based risks. It uses machine learning to identify suspicious activities like compromised credentials and unusual sign-in locations.
- Detects identity-based risks automatically.
- Integrates with Conditional Access for enforcement.
- Identifies vulnerabilities like weak passwords or multi-factor authentication not registered.
Memory trick: Identity Protection: Your digital detective for suspicious user activity.