MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are configuring Microsoft Entra ID Protection. You want to automatically respond to a specific risk level by requiring the user to change their password. Which risk policy should you configure?
⚠ Common exam trap
MS-102 often tests the confusion between user risk and sign-in risk policies — candidates must remember that password change is tied to user risk, while MFA is tied to sign-in risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User risk policy
The user risk policy in Microsoft Entra ID Protection is designed to respond to user risk detections such as leaked credentials, and it can be configured to require a password change (password reset) when a specified user risk level is reached. This directly matches the requirement to automatically respond to a risk level by requiring a password change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MFA registration policy
Why it's wrong here
The MFA registration policy prompts users to register authentication methods for future MFA, and cannot require a password change. It is the correct choice when you want to drive MFA registration coverage across your tenant.
- ✗
Sign-in risk policy
Why it's wrong here
Sign-in risk policy responds to suspicious authentication attempts by requiring MFA or blocking the sign-in, not by resetting credentials. It is the correct choice when the risk is tied to a specific sign-in rather than to the user account itself.
- ✗
Session risk policy
Why it's wrong here
Session risk policy governs sign-in session behaviour, such as requiring reauthentication or blocking access, and cannot force a password change. It is the correct choice when you want to limit or revoke an existing session based on elevated session risk.
- ✓
User risk policy
Why this is correct
User risk policy targets the user account itself, so its remediation action is a password change, satisfying the stem's requirement. Sign-in risk policy instead blocks or demands MFA at authentication, which cannot force a credential reset. Configuring user risk to High and allowing password change enforces the required response.
Go deeper
Related to this question
Learn chapter
Entra Connect Cloud Sync
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.