Courseiva

Suspend User Access Based on Identity Risk

Your company uses Microsoft Defender for Cloud Apps (MDA). You need to create a policy that automatically suspends a user's access to a cloud app if the user is confirmed as compromised by Microsoft Entra ID Protection. Which policy type should you use?

Quick Answer

The answer is a session policy. This is correct because a session policy in Microsoft Defender for Cloud Apps operates in real time, intercepting user activity and applying conditional access controls based on risk signals from Microsoft Entra ID Protection. When a user is confirmed as compromised, the session policy can automatically suspend access to cloud apps by blocking the session or forcing reauthentication, directly addressing the need to suspend user access based on identity risk. On the Microsoft Cybersecurity Architect exam, this tests your understanding of how Defender for Cloud Apps integrates with Entra ID Protection for automated remediation, often appearing as a scenario where you must distinguish session policies from access or app discovery policies. A common trap is choosing an access policy, which controls initial sign-in but cannot react to mid-session risk changes like a session policy can. Memory tip: think of a session policy as the “bouncer” that can kick a user out mid-session, while an access policy only checks the ID at the door.

⚠ Common exam trap

A common mix-up: candidates confuse session policies with access policies, assuming access policies handle user risk-based suspension, but access policies lack the real-time session control and direct Entra ID Protection integration that session policies provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Session policy

A session policy in Microsoft Defender for Cloud Apps can be configured to take real-time actions based on risk signals from Microsoft Entra ID Protection. When a user is confirmed as compromised, a session policy can enforce automatic suspension of access to cloud apps by blocking the session or requiring reauthentication, directly addressing the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Session policy

    Why this is correct

    Session policies can use risk from Microsoft Entra ID Protection to block access.

  • Access policy

    Why it's wrong here

    Access policies control access based on conditions like device state, not risk.

  • App permissions policy

    Why it's wrong here

    This manages OAuth app permissions, not user risk.

  • Anomaly detection policy

    Why it's wrong here

    This detects behavioral anomalies but does not integrate directly with identity risk.

About these practice questions

Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Microsoft Defender for Cloud Apps to monitor SaaS apps. They discover that a user is downloading large volumes of data from SharePoint Online from an atypical IP address. The security team wants to automatically suspend the user's access to all cloud apps. What is the most efficient way to achieve this?

hard
  • A.Tag the user as suspicious using an app tag.
  • B.Create a file policy that triggers when a user downloads many files.
  • C.Create a session policy that blocks the user's session based on the anomaly.
  • D.Create an OAuth app policy to revoke permissions.

Why C: Session policies in Microsoft Defender for Cloud Apps enforce real-time controls and can block a user's session based on anomalous behavior, such as downloading large volumes from an atypical IP. Option A is wrong because app tags categorize apps, not users. Option B is wrong because file policies control data at rest, not user access. Option D is wrong because OAuth app policies manage third-party app permissions, not user access suspension.

Variation 2. Your company uses Microsoft Defender for Cloud Apps and wants to prevent users from uploading sensitive files to personal cloud storage apps. What should you configure?

medium
  • A.Activity policy
  • B.App connector
  • C.Session policy
  • D.File policy

Why C: Session policy in Microsoft Defender for Cloud Apps allows real-time monitoring and control of user activities based on app and content inspection. By configuring a session policy, you can block or restrict uploads of sensitive files to personal cloud storage apps like Dropbox or Google Drive during the user's session, leveraging reverse proxy capabilities to inspect and intervene in traffic.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.