Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically detect sign-in risks such as sign-ins from unfamiliar locations, anonymous IP addresses, or leaked credentials. Based on the risk level, they want to apply different controls: for low-risk sign-ins, show a message but allow access; for medium-risk sign-ins, require multi-factor authentication (MFA); for high-risk sign-ins, block the sign-in. They also need to receive a weekly summary report of risk events. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

Many exam-takers confuse Identity Protection (the detection engine) with Conditional Access (the enforcement engine), assuming Identity Protection alone can apply the per-risk-level controls, when in reality Conditional Access policies are required to map risk levels to specific actions like MFA or block.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Conditional Access policies with sign-in risk conditions

Microsoft Entra ID Conditional Access policies can integrate sign-in risk conditions from Identity Protection to enforce granular controls based on risk levels. This allows you to configure actions such as showing a message for low risk, requiring MFA for medium risk, and blocking access for high risk, while Identity Protection provides the weekly summary report of risk events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Identity Protection policies

    Why it's wrong here

    Identity Protection is a risk-detection engine that flags issues such as impossible travel or leaked credentials, but it does not directly enforce access controls. Although it contains 'user risk policy' and 'sign-in risk policy' templates, those are actually Conditional Access policy templates, so enforcing block/MFA always happens via Conditional Access. By itself, Identity Protection cannot produce a weekly risk summary without Conditional Access having acted on the risks; the summary report aggregates the resulting decisions.

  • Microsoft Entra ID Conditional Access policies with sign-in risk conditions

    Why this is correct

    Conditional Access policies can evaluate sign-in risk levels (low, medium, high) from Identity Protection and apply granular controls such as block, require MFA, or session controls. Combined with Identity Protection reports, you get the weekly summary.

  • Microsoft Entra ID Access Reviews

    Why it's wrong here

    Access Reviews is a governance feature for periodically certifying existing user permissions — e.g., group memberships or application assignments — based on specified schedules like weekly or monthly. It focuses on whether a user should still have access, not on the risk level of each authentication event, so it cannot detect or respond to risky sign-ins. Therefore, while it might provide a 'weekly' activity, it does not summarize sign-in risk or trigger risk-based controls such as MFA.

  • Microsoft Entra ID Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) governs privileged roles through just-in-time activation, time-bound assignments, and approval workflows, but it does not evaluate the risk of a sign-in or enforce risk-based access decisions. PIM may provide audit logs and alerts on role activations, yet it has no integration with Identity Protection's risk scores. Thus, PIM cannot satisfy the requirement for weekly sign-in risk summaries or risk-triggered access controls, such as those provided by Conditional Access sign-in risk policies.

About these practice questions

One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.