When configuring Conditional Access risk policies, which risk level should be assigned for users with leaked credentials?
Choose an answer
Tap an option to check your answer.
Correct answer: High.
Why this is the answer
For users with leaked credentials, a "High" risk level should be assigned in Conditional Access risk policies. This is because leaked credentials represent a significant security threat, as they could allow unauthorized access to the user's account and associated resources. Azure AD Identity Protection detects leaked credentials and flags them as a high-risk event, necessitating immediate action such as requiring a password change or blocking access. Assigning "None," "Low," or "Medium" would underestimate the severity of the threat and fail to trigger appropriate protective measures, leaving the organization vulnerable to compromise.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed