MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that a user's sign-in was blocked due to a medium user risk. However, the user claims the sign-in was legitimate. What should you do to allow future sign-ins without lowering security?
⚠ Common exam trap
Watch out — candidates often confuse 'dismissing the risk' (which only closes the alert) with 'confirming the user as safe' (which actively resets the risk state and provides feedback), leading candidates to incorrectly choose Option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Entra ID Protection reports to confirm the user as safe
When a user claims a blocked sign-in was legitimate, the proper action is to confirm the user as safe in the Microsoft Entra ID Protection reports. This action updates the risk state to 'confirmed safe', which resets the user's risk level and allows future sign-ins without lowering security. It also provides feedback to the risk detection algorithm to improve accuracy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a conditional access policy to bypass MFA for this user
Why it's wrong here
Creating a conditional access policy to bypass MFA for this user would not remediate the identity risk; it would only remove the security control from the very account that is flagged as risky. Conditional access policies enforce access decisions based on conditions like sign-in risk, but they do not alter the user's risk score or clear detections in Entra ID Protection. Bypassing MFA for a risky user increases the likelihood of unauthorized access and is explicitly counter to the principle of step-up authentication, which is the recommended response.
- ✗
Suppress the alert in Microsoft Defender XDR
Why it's wrong here
Suppressing an alert in Microsoft Defender XDR merely hides the detection from security operations; it does not change the user's risk state in Microsoft Entra ID Protection or clear the underlying risky sign-in. Defender XDR and Entra ID Protection are independent signal pipelines, so dismissing an alert on one platform leaves the identity risk intact, potentially causing the user to remain blocked by risk-based policies. This action is effectively ignoring the issue rather than resolving it, leaving the account in a compromised or suspicious state.
- ✓
Use the Microsoft Entra ID Protection reports to confirm the user as safe
Why this is correct
Using the Microsoft Entra ID Protection reports to confirm the user as safe is the correct manual remediation action when investigation shows the risk detection is a false positive or the account is validated as legitimate. Selecting 'Confirm user safe' on the Risky users report dismisses the risk, resets the user's risk level, and removes the user from the risky users list, allowing sign-ins to proceed normally without requiring a password reset. This action should be performed only after verifying the user's identity and activity, as it is a permanent dismissal that prevents risk-based conditional access policies from challenging the user in the future.
- ✗
Dismiss the risk in the Risky users report
Why it's wrong here
Dismissing the risk in the Risky users report closes the risk incident but does not mark the user as safe or clear the underlying risk from the account. Unlike 'Confirm user safe,' 'Dismiss user risk' is not a remediation step—it leaves the risk level intact and does not trigger any corrective action like a password reset. The user may therefore remain subject to additional risk-based challenges or blocks, and a genuinely compromised account could continue to be exploited without detection, making dismissal appropriate only when intentionally accepting the risk.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Usage Analytics and Reports
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.