Microsoft Entra ID Identity Protection: Automate Risk Detection and Remediation
A company uses Microsoft Entra ID. They want to automatically detect sign-ins from anonymous IP addresses, sign-ins from unfamiliar locations, and other risky activities. When such a risk is detected, they want to block the sign-in or require multi-factor authentication. They also need a dashboard to review risk events. Which Microsoft Entra ID feature should they use?
Quick Answer
The answer is Microsoft Entra ID Identity Protection, the correct feature for automatically detecting and remediating identity-based risks like sign-ins from anonymous IP addresses or unfamiliar locations. This service works by analyzing each authentication attempt against Microsoft’s global threat intelligence and user behavior patterns, assigning a risk level that triggers a conditional access policy to block the sign-in or require multi-factor authentication. On the AZ-305 exam, this scenario tests your understanding of how to integrate risk detection into an identity governance strategy, often appearing as a distractor against standalone Conditional Access policies—remember that Identity Protection provides the risk signals, while Conditional Access enforces the action. A common trap is confusing Identity Protection with Privileged Identity Management; the former focuses on risky sign-ins and users, the latter on just-in-time admin roles. Memory tip: think of Identity Protection as the “risk radar” that feeds your Conditional Access “response system.”
⚠ Common exam trap
Watch out — candidates often confuse Conditional Access (which enforces policies) with Identity Protection (which provides the risk detection signals), leading them to select Conditional Access as the answer when the question explicitly asks for the feature that detects risks and provides a dashboard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Identity Protection
Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to detect and respond to identity-based risks such as sign-ins from anonymous IP addresses, unfamiliar locations, and other risky activities. It provides a risk-based conditional access policy that can automatically block sign-ins or require multi-factor authentication (MFA) when a risk is detected, and it includes a dashboard for reviewing risk events and reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access enforces access decisions using signals, but it does not itself detect anonymous IP or unfamiliar-location sign-ins, nor provide a risk dashboard. It is tempting because it can block sign-ins and require MFA. Identity Protection performs the detection, risk scoring and reporting that this scenario requires.
- ✓
Microsoft Entra ID Identity Protection
Why this is correct
Identity Protection detects anonymous IP sign-ins, unfamiliar locations and other risky activities, then applies risk-based policies to block sign-ins or require multi-factor authentication. Its dashboard surfaces detected risk events, satisfying every stated requirement within Microsoft Entra ID.
- ✗
Microsoft Entra ID Privileged Identity Management (PIM)
Why it's wrong here
PIM governs activation and approval of privileged role assignments; it neither detects risky sign-ins nor offers a risk-event dashboard. It is tempting because it strengthens identity security and is often deployed alongside risk policies. Identity Protection supplies the sign-in risk detection and remediation this scenario demands.
- ✗
Microsoft Entra ID Access Reviews
Why it's wrong here
Access Reviews periodically recertify group, role and application assignments; they do not analyse sign-in signals or block authentication. They are tempting because they reduce standing access, which suits periodic entitlement attestation. Identity Protection detects anonymous IP and unfamiliar-location risk and drives the required MFA or block.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-305
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Entra ID Premium P2. They need to automatically detect users with high-risk sign-ins (e.g., from anonymous IP addresses or leaked credentials) and require them to reset their password. Which Microsoft Entra ID feature should they configure?
medium- ✓ A.Identity Protection
- B.Privileged Identity Management
- C.Conditional Access
- D.Access Reviews
Why A: Identity Protection is the correct feature because it is specifically designed to detect and remediate risky sign-ins, including those from anonymous IP addresses or leaked credentials. It uses machine learning to assign a risk level to each sign-in and user, and can automatically enforce password resets when high-risk events are detected, aligning with the requirement for automated detection and remediation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.