You need to reduce account takeover risk using Microsoft Entra ID Protection. Requirements: block or interrupt risky sessions, require password change when a user is confirmed high-risk, and require MFA for medium and above sign-in risk. What should you implement? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the User risk policy to require a secure password change for High user risk and scope it to all users except a break-glass group, Enable the Sign-in risk policy to require MFA for Medium and above sign-in risk and scope it to all users except service accounts.
Why this is the answer
The User risk policy in Microsoft Entra ID Protection directly addresses the requirement to require a password change for high-risk users. Scoping it to all users except a break-glass group is a standard best practice for such policies. The Sign-in risk policy directly addresses the requirement to require MFA for medium and above sign-in risk. Scoping it to all users except service accounts prevents disruption to automated processes. Turning on security defaults enforces MFA but doesn't specifically address risk-based password changes or sign-in risk levels. Creating a Conditional Access policy to block high sign-in risk users is too restrictive; the requirement is to require MFA for medium and above, not block. The legacy per-user MFA portal is not a risk-based solution and is not recommended for new configurations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed