AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They want to enable users to reset their own passwords without contacting the help desk. They also want to enforce multi-factor authentication (MFA) during the password reset process. Which Microsoft Entra ID feature should they enable?
⚠ Common exam trap
A common mix-up: candidates confuse Conditional Access as the sole solution for password reset, but Conditional Access only enforces policies on top of SSPR; without SSPR enabled, users cannot reset their own passwords at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Self-Service Password Reset (SSPR)
Microsoft Entra ID Self-Service Password Reset (SSPR) enables users to reset their own passwords without help desk intervention. When combined with Microsoft Entra ID Conditional Access, SSPR can enforce multi-factor authentication (MFA) during the password reset process, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Identity Protection
Why it's wrong here
Microsoft Entra ID Identity Protection is a risk-detection service that analyzes sign-in events and user behavior for signals such as leaked credentials, impossible travel, and anonymous IP addresses. While it can trigger a Conditional Access policy that forces a password change for users flagged with high risk, the actual reset is performed by SSPR after the user authenticates—Identity Protection does not provide a self-service portal or manage the authentication-method verification. Thus, enabling Identity Protection alone cannot satisfy a requirement for users to reset their own passwords; it only identifies risk and triggers remediation that depends on a different feature.
- ✗
Microsoft Entra ID Privileged Identity Management (PIM)
Why it's wrong here
Privileged Identity Management (PIM) provides just-in-time privileged role activation and access reviews, not self-service password reset or MFA enforcement during that reset. It is tempting because PIM does enforce MFA for activating elevated roles, which might appear to satisfy the MFA requirement. However, the scenario demands MFA specifically during the password reset flow, which PIM does not control; that function belongs to Microsoft Entra ID’s combined registration and self-service password reset (SSPR) policy.
- ✓
Microsoft Entra ID Self-Service Password Reset (SSPR)
Why this is correct
SSPR is the Microsoft Entra ID feature purpose-built for end users to unlock or reset their own passwords without helpdesk intervention, and it can enforce multi-factor authentication as part of the reset flow. When combined with the combined registration experience, users register their MFA methods once, and administrators can require two or more verification methods in the SSPR policy, meaning the user must prove possession of multiple factors before the password is changed. This directly satisfies both the need for self-service reset and the need to enforce MFA during that reset, because the verification gate is an integral part of SSPR itself.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access is a policy engine in Microsoft Entra ID that applies real-time conditions—such as user location, device compliance, application, and sign-in risk—to allow or deny access to cloud apps. It can be used to require MFA when a user opens the password-reset portal, but it does not contain the password-reset workflow or the logic that verifies a user's registered authentication methods. Since the scenario is about enabling users to reset their own passwords, not just wrapping an additional policy around an existing sign-in, Conditional Access lacks the actual reset capability and is therefore not the correct answer.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.