nerdexam
Microsoft

MS-900 · Question #106

Your company purchases Microsoft 365 Enterprise and Azure AD P2 licenses. You need to provide identity protection against malicious login attempts. What should you implement?

The correct answer is A. Azure AD Identity Protection. Azure AD Identity Protection uses machine learning to detect and respond to identity-based risks such as malicious login attempts and compromised credentials. This feature is included with Azure AD P2 licensing.

Submitted by asante_acc· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Your company purchases Microsoft 365 Enterprise and Azure AD P2 licenses. You need to provide identity protection against malicious login attempts. What should you implement?

Options

  • AAzure AD Identity Protection
  • BAzure AD Privileged Identity Management
  • CAzure Information Protection
  • DAzure Identity and Access Management

How the community answered

(54 responses)
  • A
    87% (47)
  • B
    4% (2)
  • C
    7% (4)
  • D
    2% (1)

Why each option

Azure AD Identity Protection uses machine learning to detect and respond to identity-based risks such as malicious login attempts and compromised credentials. This feature is included with Azure AD P2 licensing.

AAzure AD Identity ProtectionCorrect

Azure AD Identity Protection is specifically designed to detect identity-based risks, including malicious login attempts, suspicious sign-in behavior, and leaked credentials. It uses Microsoft's threat intelligence and machine learning to automatically detect risk events and allows administrators to configure risk-based Conditional Access policies to remediate threats. This feature requires Azure AD P2 licensing, which the company already possesses.

BAzure AD Privileged Identity Management

Azure AD Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within Azure AD and Azure resources, but does not provide protection against malicious login attempts or identity risk detection.

CAzure Information Protection

Azure Information Protection (AIP) is a cloud-based solution for classifying, labeling, and protecting documents and emails based on sensitivity, and has no functionality related to detecting or blocking malicious authentication attempts.

DAzure Identity and Access Management

Azure Identity and Access Management is a broad conceptual framework and set of capabilities built into Azure AD rather than a specific, discrete service; it does not specifically address identity threat detection and protection against malicious logins as a standalone feature.

Concept tested: Azure AD Identity Protection for risk-based sign-in security

Source: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection

Topics

#Azure AD Identity Protection#malicious login attempts#Azure AD P2#identity security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice