nerdexam
Microsoft

MS-900 · Question #108

A company deploys Microsoft Azure AD. You run the Identity Secure Score report. The report displays five security items. Which three security items on the report have the most impact on the score? Eac

The correct answer is A. Enable policy to block legacy authentication. C. Require multi-factor authentication for all users. E. Do not expire passwords.. The Identity Secure Score in Azure AD ranks security improvement actions by their impact, with blocking legacy authentication, requiring MFA for all users, and not expiring passwords being the highest-impact items.

Submitted by viktor_hu· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company deploys Microsoft Azure AD. You run the Identity Secure Score report. The report displays five security items. Which three security items on the report have the most impact on the score? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • AEnable policy to block legacy authentication.
  • BEnable user risk policy.
  • CRequire multi-factor authentication for all users.
  • DDelete/block accounts not used in last 30 days.
  • EDo not expire passwords.

How the community answered

(44 responses)
  • A
    75% (33)
  • B
    7% (3)
  • D
    18% (8)

Why each option

The Identity Secure Score in Azure AD ranks security improvement actions by their impact, with blocking legacy authentication, requiring MFA for all users, and not expiring passwords being the highest-impact items.

AEnable policy to block legacy authentication.Correct

Blocking legacy authentication is a high-impact action because legacy protocols like POP, IMAP, and SMTP cannot enforce MFA, making them a major attack vector that significantly weakens overall identity security.

BEnable user risk policy.

Enabling user risk policy is an important security measure but has a lower impact score compared to the three correct answers in Microsoft's Identity Secure Score ranking.

CRequire multi-factor authentication for all users.Correct

Requiring multi-factor authentication for all users is one of the highest-impact security improvements because it directly mitigates credential-based attacks, which account for the majority of identity compromises.

DDelete/block accounts not used in last 30 days.

Deleting or blocking unused accounts is a good security hygiene practice but carries a lower impact weight in the Identity Secure Score compared to blocking legacy auth, enforcing MFA, and eliminating password expiration.

EDo not expire passwords.Correct

Not expiring passwords aligns with modern NIST guidelines and Microsoft's recommendations, as forced password expiration leads to weaker passwords and predictable patterns, reducing overall security posture.

Concept tested: Azure AD Identity Secure Score improvement actions and impact ranking

Source: https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-identity-secure-score

Topics

#Azure AD Secure Score#MFA#legacy authentication#password policies

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice