Drag steps to the numbered slots on the right, or tap a step then tap a slot.
AZ-500 Secure compute, storage, and databases Practice Question
Drag and drop the steps to implement Azure AD Identity Protection to detect risky sign-ins into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
1. Navigate to Azure AD Security 2. Configure user risk policy 3. Configure sign-in risk policy 4. Review risk detections
Identity Protection policies are configured under Security, with user risk policy settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
1. Navigate to Azure AD Security 2. Configure user risk policy 3. Configure sign-in risk policy 4. Review risk detections
Why this is correct
This order correctly starts by accessing the Azure AD Security blade to find Identity Protection settings. The user risk policy is configured first because it governs actions based on user risk, which is assessed from sign-ins. Then the sign-in risk policy is set to respond to risky sign-in events. Finally, reviewing risk detections ensures monitoring and validation.
- ✗
1. Configure sign-in risk policy 2. Configure user risk policy 3. Navigate to Azure AD Security 4. Review risk detections
Why it's wrong here
This is incorrect because the policies cannot be configured before navigating to the correct location. Also, the sign-in risk policy should typically be set after the user risk policy as user risk is a higher-level condition.
- ✗
1. Review risk detections 2. Navigate to Azure AD Security 3. Configure user risk policy 4. Configure sign-in risk policy
Why it's wrong here
This order is invalid because reviewing risk detections before any policies are configured is premature. Azure AD Identity Protection only generates meaningful risk detections after the user risk and sign-in risk policies are enabled and actively evaluating sign-in events; without policies, there is no risk scoring or detection logic producing the detections you would review. Even if existing detections were visible, you must first access the Azure AD Security blade to locate Identity Protection, then configure policies to establish the thresholds that make the review actionable. The correct sequence is to navigate to Azure AD Security, configure user risk, configure sign-in risk, and only then review risk detections.
- ✗
1. Configure user risk policy 2. Navigate to Azure AD Security 3. Configure sign-in risk policy 4. Review risk detections
Why it's wrong here
This order is incorrect because you cannot configure a user risk policy before navigating to the Azure AD Security blade—the policy settings reside under Identity Protection, which is only accessible from that blade. Additionally, the user risk policy is a higher-level assessment that aggregates sign-in risks, so it must be configured before the sign-in risk policy to define the conditional access response for compromised accounts. Placing navigation after the first policy breaks the required dependency, as the policy configuration step has no valid context in the Azure portal. The correct sequence starts with navigating to Azure AD Security, then configuring user risk, then sign-in risk, and finally reviewing detections.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.