MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are implementing Microsoft Entra Identity Protection. You need to configure automated responses to medium and high user risk. Which policy should you create?
⚠ Common exam trap
A common mix-up: candidates confuse User risk policy (which responds to user-level risk like compromised accounts) with Sign-in risk policy (which responds to session-level risk like suspicious sign-in attempts), leading candidates to incorrectly choose the sign-in risk policy for user risk remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User risk policy
User risk policy in Microsoft Entra Identity Protection is specifically designed to automatically respond to user risk levels (low, medium, high) by triggering remediation actions such as requiring a password change or blocking sign-in. Since the question asks for automated responses to medium and high user risk, the correct policy is the User risk policy, which evaluates risk based on user behavior and leaked credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sign-in risk policy
Why it's wrong here
The sign-in risk policy is designed to evaluate the probability that each specific authentication attempt is unauthorized, using real-time signals such as impossible travel or anonymous IP addresses. It does not aggregate or respond to the cumulative risk profile of a user across multiple detections, which is the definition of user risk. Since the question specifically asks about responding to user risk levels, this policy is not the appropriate choice.
- ✗
Conditional Access policy with grant controls
Why it's wrong here
A Conditional Access policy with grant controls is a flexible mechanism that can incorporate sign-in risk as a condition and enforce actions such as require MFA or block. However, it lacks the dedicated automation and lifecycle for user risk that Identity Protection provides, including automatic risk state updates and self-remediation flows like password change. Microsoft positions the user risk policy as the specific tool for responding to user risk, making a customized CA policy a less direct answer.
- ✗
MFA registration policy
Why it's wrong here
The MFA registration policy is an Identity Protection feature that mandates users enroll in Microsoft Entra Multifactor Authentication before their first interactive sign-in. It addresses readiness for authentication challenges, not the detection or mitigation of an already compromised identity. Because the scenario is about responding to a high user risk level, this policy does not offer any risk-based assessment or active response, so it cannot accomplish the requirement.
- ✓
User risk policy
Why this is correct
The user risk policy responds to the aggregate probability that a user's identity has been compromised, based on multiple risk detections associated with that account. It can be configured to automatically block all access or trigger a secure password change with required MFA, based on the user risk level (low, medium, high). This is precisely the Microsoft Entra ID Protection mechanism designed for user risk levels, making it the correct answer.
Go deeper
Related to this question
Learn chapter
Insider Risk Management
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.