MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Fabrikam Inc. is a technology company that uses Microsoft 365 E5. They have implemented Microsoft Defender XDR to monitor for threats. The security team wants to receive alerts when a user is compromised, such as when a user's credentials are used from an unusual location. They also want to automatically block the user from signing in until the risk is mitigated. You need to configure a solution that automatically detects and responds to such identity risks. What should you configure?
⚠ Common exam trap
MS-900 often tests the difference between Identity Protection and Conditional Access; candidates may choose a generic MFA policy instead of the risk-based policy that automatically blocks high-risk users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Identity Protection in Microsoft Entra ID to detect risky sign-ins and enable the 'User risk policy' to automatically block high-risk users.
Microsoft Entra ID Identity Protection detects risky sign-ins and user risk, and allows configuring risk policies to automatically block or require password change for high-risk users. The 'User risk policy' can block access when user risk is high, which meets the requirement to automatically block compromised users. This is the native solution for identity risk detection and response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Defender for Cloud Apps to monitor user activities.
Why it's wrong here
Defender for Cloud Apps monitors SaaS activity and shadow IT; it neither computes sign-in risk nor blocks authentication. It is tempting because it surfaces anomalous user behaviour, and would be correct for discovering unsanctioned cloud apps or investigating session activity after access is granted.
- ✓
Configure Identity Protection in Microsoft Entra ID to detect risky sign-ins and enable the 'User risk policy' to automatically block high-risk users.
Why this is correct
Identity Protection evaluates sign-in telemetry for anomalous location and other risk signals, raising user risk automatically. The user risk policy then enforces the required response, blocking high-risk accounts from signing in until remediation, which meets the automatic detection and blocking requirement.
- ✗
Deploy Microsoft Sentinel and create analytics rules to detect and respond to identity threats.
Why it's wrong here
Sentinel analytics rules detect and raise incidents but do not natively block a risky user's sign-in; that response requires Entra ID Protection risk policies. It is tempting because Sentinel correlates identity signals, and would be correct for centralised SIEM detection and custom automated playbooks.
- ✗
Create a Conditional Access policy that requires MFA for all sign-ins.
Why it's wrong here
Requiring MFA for all sign-ins challenges every user regardless of risk and never blocks a compromised account until remediation. It is tempting because MFA hardens sign-ins generally, and would suit enforcing baseline authentication strength rather than responding to detected identity risk.
Go deeper
Related to this question
Learn chapter
Exchange Online Protection (EOP)
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.