MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that the number of 'Leaked Credentials' detections is high. What action should you take to automatically remediate this risk?
⚠ Common exam trap
Many exam-takers confuse 'automatic password reset' (which is not supported) with 'requiring a password change' (which is supported via a user risk policy), leading them to select Option A instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users
A user risk policy in Microsoft Entra ID Protection can be configured to automatically trigger a password change when a user is detected as high risk, such as when leaked credentials are identified. This policy directly remediates the risk by forcing the user to update their compromised credentials, effectively invalidating the leaked password. The other options either do not address the root cause or require manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Entra ID Protection to automatically reset passwords for all users with leaked credentials
Why it's wrong here
Microsoft Entra ID Protection does not offer a built-in action to automatically reset passwords for all users with leaked credentials. It detects leaked credentials and assigns a user risk level, but remediation still requires a user risk policy that is configured with 'Require password change' as the targeted access control. Without such a policy, no password reset occurs, and the leaked credentials remain valid for continued use.
- ✗
Configure a conditional access policy to block access for users with high user risk
Why it's wrong here
Configuring a Conditional Access policy to block high-user-risk users is an acceptable risk-based response, but it does not remediate the underlying leaked credentials. The user's password remains compromised, so the risk is only suppressed while the block is in force; an attacker who has the password still possesses valid authentication material. Conditional Access can gate access based on user risk, but remediation requires a separate user risk policy action such as forcing a password change.
- ✓
Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users
Why this is correct
The correct remediation is to configure a user risk policy in Microsoft Entra ID Protection that assigns 'Require password change' as the access control for high-risk users. When a user is flagged for leaked credentials, this policy forces the user to complete a password change the next time they sign in, which revokes the compromised password and automatically lowers the user's risk back to normal. This is the only built-in, automatically enforced way to remediate leaked credentials in Entra ID.
- ✗
Enable Microsoft Entra ID Multifactor Authentication for all users
Why it's wrong here
Enabling Microsoft Entra ID Multifactor Authentication for all users does not remediate leaked credentials because the compromised password itself is never changed. MFA only requires an additional verification factor, so it may block a simple password replay, but an attacker with the leaked password and possession of the account still has the original credential material. MFA is a valuable security control, but the leaked credential must be invalidated through a forced password reset to truly resolve the risk.
Go deeper
Related to this question
Learn chapter
Entra Connect Health Monitoring
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.