AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Microsoft Entra ID for identity management. You need to implement a solution that automatically blocks sign-ins from risky users and requires multi-factor authentication (MFA) when a sign-in risk is detected. Which TWO services should you use? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Microsoft Defender XDR (which includes identity threat detection) with the policy enforcement layer, but only Conditional Access policies can apply the automated MFA or block action based on risk from Entra ID Protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Protection
Microsoft Entra ID Protection (B) is the service that detects sign-in risks (e.g., anonymous IP, atypical travel) and labels users or sign-ins as risky. Conditional Access policies (E) then enforce automated responses, such as blocking the sign-in or requiring MFA, based on the risk level from Entra ID Protection. Together, they provide the detection and enforcement mechanism described in the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a data governance, risk, and compliance solution that focuses on data classification, sensitivity labels, data loss prevention, and audit, not on analyzing authentication risk or enforcing risk-based access decisions. Although it can ingest Entra ID audit logs and support eDiscovery or compliance investigations, it does not evaluate user risk or sign-in risk in real time, and it cannot block a compromised session based on identity risk signals.
- ✓
Microsoft Entra ID Protection
Why this is correct
Microsoft Entra ID Protection is the dedicated identity risk engine that continuously analyzes user and sign-in behavior using signals such as leaked credentials, impossible travel, anomalous token usage, and unfamiliar properties. It calculates user risk and sign-in risk levels and automatically remediates or responds to these risks by requiring MFA or password change, or by blocking access via Conditional Access policies. This makes it the correct service for detecting risky users and risky sign-ins in a Microsoft Entra ID environment.
- ✗
Microsoft Defender XDR
Why it's wrong here
Microsoft Defender XDR is an enterprise threat protection suite that ingests and correlates security telemetry across endpoints, email, cloud apps, and identity to help security operations teams detect, investigate, and respond to active incidents. While it can surface identity alerts for incident review, it does not perform the real-time risk score calculation or risk-level categorization that Entra ID Protection performs, and it is not designed to enforce access policies at the moment of sign-in. Its focus is on post-compromise detection and response, not on proactive risk-based access control.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance, configuration profiles, and app protection policies, but it does not analyze identity-specific risk signals. Intune's device compliance status can be used as a condition in a Conditional Access policy, but Intune itself does not determine whether a user's account or sign-in is risky, nor does it generate user-risk scores. Therefore, it is not the tool for detecting risky users or sign-ins.
- ✓
Conditional Access policies
Why this is correct
Conditional Access is the policy enforcement engine in Microsoft Entra ID that applies rules based on signals such as user risk, sign-in risk, device compliance, and location. It is correct in this context because it uses the risk signals generated by Entra ID Protection to enforce actions like requiring MFA, forcing a password change, or blocking access, making it an active part of risk-based access control. However, the actual detection and risk scoring of risky users and sign-ins is performed by Entra ID Protection, so Conditional Access is the enforcement layer, not the detection engine.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 212 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.