MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft Entra ID P2 and has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement a solution that automatically remediates risky user sign-ins by requiring a password change when Microsoft Entra ID Protection detects a leaked credential. You also want to minimize help desk calls. Which configuration should you use?
⚠ Common exam trap
A common mix-up: candidates confuse sign-in risk policies with user risk policies; leaked credentials raise user risk, not sign-in risk, so a sign-in risk policy will not force a password change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a user risk policy in Microsoft Entra ID Protection to require a secure password change for high user risk, and enable self-service password reset (SSPR) so users can remediate themselves.
Microsoft Entra ID Protection detects leaked credentials and raises user risk. A user risk policy configured to require a secure password change for high user risk enforces remediation, and enabling SSPR lets users reset their own passwords. This combination automatically addresses the risk and reduces help desk dependency, which is exactly what the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a user risk policy in Microsoft Entra ID Protection to require a secure password change for high user risk, and enable self-service password reset (SSPR) so users can remediate themselves.
Why this is correct
A user risk policy set to require a secure password change for high-risk users responds to leaked credentials by forcing a password reset. Enabling SSPR allows users to complete the remediation without help desk involvement, satisfying both the security and the minimize-help-desk-calls requirements. This is the intended use of Identity Protection user risk policies.
- ✗
Create a Conditional Access policy that requires multifactor authentication for all users and enable risk detections in Microsoft Entra ID Protection.
Why it's wrong here
Requiring MFA for all users does not remediate a leaked credential by forcing a password change. It may reduce risk, but the leaked password remains valid and could be used in other contexts. The requirement specifically asks to force a password change when a leaked credential is detected, which MFA alone does not accomplish.
- ✗
Enable Microsoft Entra Connect Health and configure alert notifications for synchronization errors, then instruct users to change their passwords when alerts are received.
Why it's wrong here
Entra Connect Health monitors synchronization and provides alerts, but it is not an Identity Protection remediation mechanism. It does not detect leaked credentials or automatically require a password change. Relying on manual user action after alerts would increase help desk calls and does not provide automated remediation as required.
- ✗
Configure a sign-in risk policy to block access for medium and high sign-in risk, and enable Microsoft Entra Password Protection with a custom banned password list.
Why it's wrong here
A sign-in risk policy blocks sessions based on sign-in risk, but it does not force a password change for a leaked credential. Password Protection prevents weak passwords from being set but does not remediate an already compromised account. The combination does not meet the requirement to automatically require a password change upon leaked credential detection.
Go deeper
Related to this question
Learn chapter
Entra Connect Cloud Sync
Key term
Hybrid identity
Hybrid identity is an approach that synchronizes and manages user identities across both on-premises directories and cloud-based services, allowing seamless access to resources in both environments.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.