Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID Premium P2. They need to automatically detect users with high-risk sign-ins (e.g., from anonymous IP addresses or leaked credentials) and require them to reset their password. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

It's easy for candidates to confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement engine that requires Identity Protection to first detect and assign the risk level, making Identity Protection the correct feature for automatic detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity Protection

Identity Protection is the correct feature because it is specifically designed to detect and remediate risky sign-ins, including those from anonymous IP addresses or leaked credentials. It uses machine learning to assign a risk level to each sign-in and user, and can automatically enforce password resets when high-risk events are detected, aligning with the requirement for automated detection and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity Protection

    Why this is correct

    Identity Protection in Microsoft Entra ID Premium P2 continuously evaluates user and sign-in risk signals, such as leaked credentials and impossible travel. Its risk policies can automatically trigger a secure password change for high user risk, remediating compromised accounts without manual intervention. This automated remediation capability is exactly what the company needs.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) narrowly governs time-bound activation and just-in-time elevation of privileged Microsoft Entra ID roles, like Global Administrator. PIM requires approvals and provides audit logs for role assignments, but it has no mechanism to analyze general user risk or force password resets for standard users. Thus, it cannot address the company's requirement for automated identity risk remediation.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access is a policy engine that enforces conditions at sign-in, such as requiring MFA, blocking access, or restricting sessions based on sign-in risk. It does not implement remediation workflows; it only grants or denies access at authentication time. Moreover, to force a password change, you need Identity Protection's user risk policy, not Conditional Access alone, so it cannot deliver the required automatic password reset.

  • ✗

    Access Reviews

    Why it's wrong here

    Access Reviews are a governance feature used to periodically recertify who should retain access to groups, apps, and roles. These reviews require scheduled human reviewers to approve or remove entitlements, making them a manual, time-based control rather than an automated response to emerging security risks. They neither detect identity risk nor trigger remediation actions such as password resets.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.