Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator. You need to configure a policy that automatically blocks sign-ins from anonymous IP addresses for all users in your Microsoft 365 tenant. Which policy should you configure in Microsoft Entra ID?

⚠ Common exam trap

MS-102 often tests the distinction between sign-in risk (real-time authentication signals like anonymous IP) and user risk (compromised credential indicators), causing candidates to pick the wrong condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policy with sign-in risk condition

Anonymous IP address sign-ins are a sign-in risk detection in Microsoft Entra ID Protection. To automatically block them for all users, you configure a Conditional Access policy that targets All users and uses the sign-in risk condition set to High (or the specific 'Anonymous IP address' risk), with the access control set to Block. Sign-in risk evaluates the authentication attempt itself, which is exactly what anonymous IP represents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password protection policy

    Why it's wrong here

    Password protection policies enforce banned-password lists and custom lockout settings; they do not evaluate sign-in origin. It is tempting because it is a tenant-wide Microsoft Entra ID security control, but it would be correct for preventing weak or banned passwords, not for blocking anonymous IP addresses.

  • ✗

    Conditional Access policy with user risk condition

    Why it's wrong here

    A Conditional Access policy with a user risk condition triggers on signals such as leaked credentials, not on the network origin of a sign-in. It is tempting because Conditional Access is the correct policy family, but anonymous IP blocking requires the sign-in risk condition or a named location condition instead.

  • ✓

    Conditional Access policy with sign-in risk condition

    Why this is correct

    A Conditional Access policy with the sign-in risk condition evaluates Microsoft Entra ID Protection signals and blocks sign-ins assessed as risky, including anonymous IP usage. Applying it to all users satisfies the requirement to automatically block anonymous-IP sign-ins tenant-wide.

  • ✗

    Identity Protection user risk policy

    Why it's wrong here

    An Identity Protection user risk policy responds to compromised-credential indicators, remediating or blocking based on user risk level, not anonymous IP origin. It is tempting because it is an automated Microsoft Entra ID sign-in control, but it would be correct for leaked-credential scenarios rather than anonymous proxy sign-ins.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.