Courseiva

AZ-305 Identity Protection Practice Question

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically detect sign-ins from users with leaked credentials and prompt those users to reset their password during the next sign-in. Which Microsoft Entra ID feature should they enable?

⚠ Common exam trap

It's easy for candidates to confuse Conditional Access (which can enforce password changes via a 'Require password change' grant control) with Identity Protection, but Conditional Access alone cannot detect leaked credentials—it only enforces policies after a risk is detected by Identity Protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Identity Protection

Microsoft Entra ID Identity Protection includes a 'Leaked Credentials' detection capability that continuously monitors for credentials exposed in known data breaches. When a user's credentials are detected as leaked, Identity Protection can automatically trigger a password reset during the next sign-in, ensuring the compromised credentials are no longer usable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID Identity Protection

    Why this is correct

    Microsoft Entra ID Identity Protection detects leaked-credential sign-ins through its leaked credentials detection signal and can enforce a user risk policy requiring password reset at next sign-in. This satisfies the requirement for automatic detection and remediation without manual monitoring.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access evaluates signals such as device compliance, location and risk to grant or block access, but it cannot itself detect leaked credentials or force a password reset. It is tempting because risk-based Conditional Access policies consume Identity Protection signals, and would be correct when the requirement is to block or require MFA for risky sign-ins.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    PIM governs just-in-time activation of privileged directory roles and approval workflows; it never inspects sign-in telemetry for compromised credentials. It is tempting because PIM hardens administrative accounts, and would be the right choice when the requirement is to eliminate standing Global Administrator assignments rather than remediate leaked user passwords.

  • ✗

    Microsoft Entra ID B2B

    Why it's wrong here

    B2B governs guest collaboration and cross-tenant invitation and redemption, not leaked-credential detection or forced password reset. It is tempting because it is an Entra ID identity feature dealing with external users, and it is correct when partners need access to your apps without separate credentials.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.