AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to automatically block sign-ins from malicious IP addresses and require users to perform multi-factor authentication (MFA) when signing in from untrusted locations. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Candidates often confuse Conditional Access (the policy engine) with the risk detection source, forgetting that Identity Protection provides the risk signals (like malicious IPs) that Conditional Access then enforces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity Protection
Identity Protection (option B) is the correct feature because it uses machine learning and heuristics to detect risky sign-ins, such as those from malicious IP addresses or untrusted locations. It can automatically block sign-ins from known malicious IPs and, when combined with Conditional Access, require MFA for sign-ins from untrusted locations. This directly addresses the requirement to block malicious IPs and enforce MFA based on location risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies are the enforcement layer that can apply session controls like 'Block access' or 'Require MFA' based on conditions such as user location, device state, and risk level. However, the automatic detection of a malicious IP address is a risk detection generated by Identity Protection, not by Conditional Access itself. Without Identity Protection feeding the risk signal into Conditional Access, the policy has no risk condition to evaluate, so the feature responsible for detecting the malicious IP is Identity Protection.
- ✓
Identity Protection
Why this is correct
Identity Protection detects risky sign-ins using detections such as 'Anonymous IP address' and 'Malicious IP address' from Microsoft Threat Intelligence, along with machine learning models that assign a risk level to each sign-in and user. In Microsoft Entra ID Premium P2, it also supports risk-based Conditional Access policies that can automatically block the risky sign-in or require MFA. This detection capability is what directly identifies a malicious IP, making Identity Protection the correct answer.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) focuses on just-in-time and time-bound activation of privileged roles, adding approval, MFA, and justification workflows for Microsoft Entra ID roles and Azure resource roles. It does not analyze sign-in risk, IP reputation, or behavioral signals; it only governs the elevation of permanent eligible assignments. Blocking a sign-in from a malicious IP is a sign-in risk response, which is outside PIM's scope entirely.
- ✗
Access Reviews
Why it's wrong here
Access Reviews are a governance workflow for periodically recertifying who still needs access to applications or groups, typically through owner attestation. They evaluate existing entitlements and memberships, not live sign-in telemetry or IP reputation. A malicious IP sign-in would not trigger an Access Review because reviews run on a schedule after the fact and are meant for access recertification, not real-time sign-in blocking.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.