nerdexam
Microsoft

MS-700 · Question #150

You have a Microsoft 365 E5 subscription that uses Teams. You need to recommend a security solution for Teams users. The solution must meet the following requirements: Detect risks, such as…

This question tests knowledge of Microsoft Entra ID Protection and Conditional Access as the solution for detecting identity risks and enforcing MFA in a Microsoft 365 E5 environment, configured via the Microsoft Entra admin center.

Configure and manage a Teams environment

Question

You have a Microsoft 365 E5 subscription that uses Teams. You need to recommend a security solution for Teams users. The solution must meet the following requirements:
  • Detect risks, such as unfamiliar sign-ins and atypical travel.
  • Enforce multi-factor authentication (MFA) when risky sign-ins are detected. What should you include in the recommendation, and which portal should you use?

Explanation

This question tests knowledge of Microsoft Entra ID Protection and Conditional Access as the solution for detecting identity risks and enforcing MFA in a Microsoft 365 E5 environment, configured via the Microsoft Entra admin center.

Approach. The correct recommendation is to use Microsoft Entra ID Protection (formerly Azure AD Identity Protection) combined with Conditional Access sign-in risk policies. Entra ID Protection natively detects risk signals such as unfamiliar sign-in properties and atypical travel by analyzing each authentication event against behavioral baselines. A Conditional Access policy is then configured to trigger MFA enforcement when the sign-in risk level meets a defined threshold (Low, Medium, or High), satisfying both requirements. Since Microsoft 365 E5 includes Entra ID P2 licensing, all these features are available at no extra cost. The correct portal to configure both features is the Microsoft Entra admin center (entra.microsoft.com), under Protection > Identity Protection and Protection > Conditional Access respectively.

Concept tested. Microsoft Entra ID Protection risk detection (unfamiliar sign-ins, atypical travel) combined with Conditional Access sign-in risk policies to enforce MFA - and knowing the Microsoft Entra admin center is the appropriate configuration portal for these features in a Microsoft 365 E5 environment.

Reference. Microsoft Learn: What is Microsoft Entra ID Protection? - https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection

Topics

#Azure AD Identity Protection#Conditional Access#Multi-factor authentication (MFA)#Identity security

Community Discussion

No community discussion yet for this question.

Full MS-700 Practice