Which TWO scenarios are addressed by Microsoft Entra ID Protection? (Choose two.)
Microsoft Entra ID Protection ingests signals indicating compromised accounts, including leaked credential pairs discovered on dark web sources. This detection surfaces as a risk detection, letting risk-based Conditional Access policies respond, which satisfies the leaked-credentials scenario named in the question.
Why this answer
Entra ID Protection is a risk-based identity protection service that detects and remediates identity risks in real time. Option A is correct because ID Protection's leaked credentials detection scans the dark web for compromised user credentials and raises a user risk when a match is found, prompting remediation such as password reset or risk-based Conditional Access. Option E is correct because ID Protection includes sign-in risk detections such as 'Anonymous IP address' (along with atypical travel, impossible travel, malware-linked IP, and unfamiliar sign-in properties) that can block or challenge sign-ins via Conditional Access policies.
Option B is not correct because reviewing group membership assignments is a governance/access-review task handled by Entra ID Access Reviews or entitlement management, not ID Protection. Option C is not correct because device compliance enforcement is handled by Microsoft Intune and Conditional Access device-compliance policies, not by ID Protection. Option D is not correct because self-service password reset (SSPR) is a separate Entra ID feature for credential recovery, not a risk detection or remediation capability of ID Protection.
Exam trap
The trap here is confusing Identity Protection's risk detection and remediation capabilities with other Microsoft Entra features like SSPR, access reviews, or device compliance, leading candidates to select options that are not part of the Identity Protection service.