Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Hard

A Microsoft 365 administrator is investigating a potential data breach where sensitive company documents were accessed from an unusual location. The administrator suspects that the user's account might be compromised. To prevent further unauthorized access and protect the organization's data, the administrator needs to ensure that if a user's sign-in activity is deemed risky, immediate action is taken, such as blocking the sign-in or forcing a password reset. Which Azure AD feature is specifically designed to detect and respond to identity-based risks in real-time?

  1. AAzure AD Privileged Identity Management (PIM)
  2. BAzure AD Security Defaults
  3. CAzure AD Conditional Access
  4. DAzure AD Identity Protection
Show answer & explanation

Correct answer: D. Azure AD Identity Protection

Azure AD Identity Protection is specifically designed to detect, investigate, and remediate identity-based risks in real-time. It uses machine learning to identify anomalous sign-in activities and user behaviors, such as sign-ins from unfamiliar locations, and can trigger automated responses like blocking access or requiring password resets.

Why the other options are wrong

  • A. Azure AD PIM manages just-in-time access for privileged roles, not real-time detection and response to compromised user accounts.
  • B. Azure AD Security Defaults provide a baseline level of security but do not offer real-time, risk-based detection and remediation for compromised accounts.
  • C. Azure AD Conditional Access applies policies based on various conditions, including risk levels reported by Identity Protection, but Identity Protection itself detects the risk.

Azure AD Identity Protection

An Azure Active Directory feature that helps detect, investigate, and remediate identity-based risks, including compromised accounts, risky sign-ins, and anomalous user behavior.

  • Uses machine learning to identify real-time and offline risks.
  • Detects risky sign-ins (e.g., impossible travel, unfamiliar locations, infected devices).
  • Detects risky users (e.g., leaked credentials).
  • Can automate remediation actions like blocking access or forcing password resets.

Memory trick: Identity Protection patrols for suspicious signs.

More Describe security, compliance, privacy, and trust in Microsoft 365 questions