Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that automatically blocks sign-ins from risky users and requires multi-factor authentication (MFA) when a sign-in risk is detected. Which TWO services should you use? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Microsoft Defender XDR (which includes identity threat detection) with the policy enforcement layer, but only Conditional Access policies can apply the automated MFA or block action based on risk from Entra ID Protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Protection

Microsoft Entra ID Protection (B) is the service that detects sign-in risks (e.g., anonymous IP, atypical travel) and labels users or sign-ins as risky. Conditional Access policies (E) then enforce automated responses, such as blocking the sign-in or requiring MFA, based on the risk level from Entra ID Protection. Together, they provide the detection and enforcement mechanism described in the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a data governance, risk, and compliance solution that focuses on data classification, sensitivity labels, data loss prevention, and audit, not on analyzing authentication risk or enforcing risk-based access decisions. Although it can ingest Entra ID audit logs and support eDiscovery or compliance investigations, it does not evaluate user risk or sign-in risk in real time, and it cannot block a compromised session based on identity risk signals.

  • Microsoft Entra ID Protection

    Why this is correct

    Microsoft Entra ID Protection is the dedicated identity risk engine that continuously analyzes user and sign-in behavior using signals such as leaked credentials, impossible travel, anomalous token usage, and unfamiliar properties. It calculates user risk and sign-in risk levels and automatically remediates or responds to these risks by requiring MFA or password change, or by blocking access via Conditional Access policies. This makes it the correct service for detecting risky users and risky sign-ins in a Microsoft Entra ID environment.

  • Microsoft Defender XDR

    Why it's wrong here

    Microsoft Defender XDR is an enterprise threat protection suite that ingests and correlates security telemetry across endpoints, email, cloud apps, and identity to help security operations teams detect, investigate, and respond to active incidents. While it can surface identity alerts for incident review, it does not perform the real-time risk score calculation or risk-level categorization that Entra ID Protection performs, and it is not designed to enforce access policies at the moment of sign-in. Its focus is on post-compromise detection and response, not on proactive risk-based access control.

  • Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance, configuration profiles, and app protection policies, but it does not analyze identity-specific risk signals. Intune's device compliance status can be used as a condition in a Conditional Access policy, but Intune itself does not determine whether a user's account or sign-in is risky, nor does it generate user-risk scores. Therefore, it is not the tool for detecting risky users or sign-ins.

  • Conditional Access policies

    Why this is correct

    Conditional Access is the policy enforcement engine in Microsoft Entra ID that applies rules based on signals such as user risk, sign-in risk, device compliance, and location. It is correct in this context because it uses the risk signals generated by Entra ID Protection to enforce actions like requiring MFA, forcing a password change, or blocking access, making it an active part of risk-based access control. However, the actual detection and risk scoring of risky users and sign-ins is performed by Entra ID Protection, so Conditional Access is the enforcement layer, not the detection engine.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 212 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.