nerdexam
Microsoft

SC-300 · Question #263

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Report suspicious activity and the legacy Fraud Alert implementation can operate in parallel. You can keep your tenant-wide Fraud Alert functionality in place while you start to use Report suspicious activity with a targeted test group. If Fraud Alert is enabled with Automatic…

Submitted by valeria.br· Mar 6, 2026Implement authentication and access management

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 tenant. All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services. Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request. You need to block the users automatically when they report an MFA request that they did not initiate. Solution: From the Azure Active Directory admin center, you configure the Block/unblock users settings for multi-factor authentication (MFA). Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(35 responses)
  • A
    31% (11)
  • B
    69% (24)

Explanation

Report suspicious activity and the legacy Fraud Alert implementation can operate in parallel. You can keep your tenant-wide Fraud Alert functionality in place while you start to use Report suspicious activity with a targeted test group. If Fraud Alert is enabled with Automatic Blocking, and Report suspicious activity is enabled, the user will be added to the blocklist and set as high-risk and in-scope for any other policies configured. These users will need to be removed from the blocklist and have their risk remediated to enable them to sign in with MFA. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-mfasettings#report- suspicious-activity-and-fraud-alert

Topics

#MFA#Microsoft Authenticator#authentication methods#Microsoft 365

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice