AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company wants to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to require multi-factor authentication (MFA) or block the sign-in in real time. Additionally, they need a dashboard that shows risk events and allows generating weekly risk reports. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
Candidates often confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that actually detects the risks and provides the risk signals that Conditional Access uses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Identity Protection
Microsoft Entra ID Identity Protection is the correct feature because it specifically detects sign-in risks such as anonymous IP addresses and unfamiliar locations, and it can automatically enforce conditional access policies like requiring MFA or blocking sign-ins in real time. It also provides a dashboard for risk events and supports generating weekly risk reports, directly matching all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Identity Protection
Why this is correct
Microsoft Entra ID Identity Protection is the dedicated detection engine that evaluates each sign-in against a set of risk signals, including the anonymous IP address signal, which flags sign-ins originating from Tor, virtual private networks (VPNs), and other IP-anonymizing services. It applies machine-learning models and heuristics to produce a risk score (Low/Medium/High) and generates a risky sign-in report, which can then trigger automated remediation such as requiring multifactor authentication (MFA) or blocking the sign-in. This is the component responsible for the underlying detection, not Conditional Access.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access is a policy enforcement platform that can consume risk signals, but it does not itself inspect the source IP to determine whether it is anonymous. It supports a condition called 'Risk based policy' (e.g., User risk or Sign-in risk), which relies on the risk assessment already produced by Identity Protection. Therefore, while Conditional Access can block or challenge a sign-in from an anonymous IP, it must first receive the risk signal from Identity Protection; it does not perform the detection autonomously.
- ✗
Microsoft Entra ID Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is focused exclusively on time-bound, just-in-time activation of privileged roles such as Global Administrator or Application Administrator, and it provides approval workflows and auditing for role assignments. It has no visibility into the network properties of a sign-in request and does not evaluate sign-in risk signals like anonymous IP addresses. Its purpose is to minimize standing privileges, not to monitor authentication events for suspicious source characteristics.
- ✗
Microsoft Entra ID Identity Governance
Why it's wrong here
Entra ID Identity Governance is an administrative framework for access lifecycle operations, including access reviews, entitlement management, and identity lifecycle workflows. It is fundamentally a governance and compliance tool, not a real-time security detection mechanism, so it does not analyze sign-in requests for anonymous IP addresses or other risk signals. While it can help clean up overprivileged accounts over time, it cannot trigger an automated response to an anonymously sourced sign-in at the moment it occurs.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.