AZ-305 Identity Protection Practice Question
A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically detect sign-ins from users with leaked credentials and prompt those users to reset their password during the next sign-in. Which Microsoft Entra ID feature should they enable?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access (which can enforce password changes via a 'Require password change' grant control) with Identity Protection, but Conditional Access alone cannot detect leaked credentials—it only enforces policies after a risk is detected by Identity Protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Identity Protection
Microsoft Entra ID Identity Protection includes a 'Leaked Credentials' detection capability that continuously monitors for credentials exposed in known data breaches. When a user's credentials are detected as leaked, Identity Protection can automatically trigger a password reset during the next sign-in, ensuring the compromised credentials are no longer usable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Identity Protection
Why this is correct
Microsoft Entra ID Identity Protection detects leaked-credential sign-ins through its leaked credentials detection signal and can enforce a user risk policy requiring password reset at next sign-in. This satisfies the requirement for automatic detection and remediation without manual monitoring.
- ✗
Conditional Access
Why it's wrong here
Conditional Access evaluates signals such as device compliance, location and risk to grant or block access, but it cannot itself detect leaked credentials or force a password reset. It is tempting because risk-based Conditional Access policies consume Identity Protection signals, and would be correct when the requirement is to block or require MFA for risky sign-ins.
- ✗
Privileged Identity Management (PIM)
Why it's wrong here
PIM governs just-in-time activation of privileged directory roles and approval workflows; it never inspects sign-in telemetry for compromised credentials. It is tempting because PIM hardens administrative accounts, and would be the right choice when the requirement is to eliminate standing Global Administrator assignments rather than remediate leaked user passwords.
- ✗
Microsoft Entra ID B2B
Why it's wrong here
B2B governs guest collaboration and cross-tenant invitation and redemption, not leaked-credential detection or forced password reset. It is tempting because it is an Entra ID identity feature dealing with external users, and it is correct when partners need access to your apps without separate credentials.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.