Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID P2 licensing. You need to ensure that when a user's risk level is detected as 'high' by Identity Protection, the user is automatically required to perform a password change during their next sign-in. Which conditional access policy configuration should you use?

⚠ Common exam trap

Many exam-takers confuse 'Sign-in risk policy' (which controls session behavior) with 'User risk policy' (which controls user-level remediation), leading candidates to incorrectly select Option A for a password change requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign 'User risk policy' with grant 'Require password change'

The 'User risk policy' in Microsoft Entra ID Conditional Access is specifically designed to respond to user-level risk detections from Identity Protection. When a user's risk level is 'high', the policy can enforce a 'Require password change' grant, which forces the user to change their password at next sign-in to remediate the compromised account. This aligns with the requirement to automatically trigger a password change based on user risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign 'Sign-in risk policy' with session control 'Sign-in frequency'

    Why it's wrong here

    Sign-in frequency is a session control that defines how often a user must reauthenticate during an active session, not a remediation action for compromised accounts. Applying it via a sign-in risk policy would only force more frequent MFA prompts, leaving the existing password unchanged and the user risk unmitigated.

  • ✓

    Assign 'User risk policy' with grant 'Require password change'

    Why this is correct

    When a user risk policy triggers a 'Require password change' grant, the user must change their password before accessing resources, which invalidates the compromised credential. This directly remediates the detected user risk because the attacker no longer knows the valid password, and is the only option listed that performs an actual password reset.

  • ✗

    Assign 'User risk policy' with grant 'Require multifactor authentication'

    Why it's wrong here

    Requiring multifactor authentication through a user risk policy adds an extra authentication factor at sign-in, but it does not alter the existing password. Since the compromised password remains valid, the attacker could still attempt to use it, and the user risk is not actually remediated; MFA only provides a conditional barrier.

  • ✗

    Assign 'User risk policy' with grant 'Block access'

    Why it's wrong here

    Blocking access via a user risk policy denies the account from signing in entirely, which prevents the legitimate user from accessing the portal to change their password. While it does protect against immediate misuse, it does not remediate the underlying risk because the password is never changed, leaving the account in a suspended state.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.