When configuring Conditional Access risk policies, which risk level should be assigned for sign-ins originating from IP addresses with suspicious activity?
Choose an answer
Tap an option to check your answer.
Correct answer: Medium.
Why this is the answer
The correct answer is Medium. Azure AD Identity Protection classifies sign-ins from IP addresses with suspicious activity as a Medium risk. This category indicates that while the activity is unusual and warrants investigation, it doesn't immediately suggest a high-confidence compromise like a sign-in from an unfamiliar location with an impossible travel scenario (which would be High risk). Low risk typically applies to less severe anomalies, such as sign-ins from infected devices that are known to be remediated. Assigning 'None' would mean no risk is detected, which is incorrect for suspicious activity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed