SC-300 · Question #301
Hotspot Question You have a Microsoft Entra tenant that contains the users shown in the following table. You have a user risk policy that has the following settings: • Assignments: o Include: Group1…
The correct answer is User1 must change their password during sign in. = Yes; User2 must change their password during sign in. = No; User3 must change their password during sign in. = No. The question tests understanding of Microsoft Entra ID Protection user risk policy evaluation, specifically how group inclusions/exclusions and risk level conditions determine if a 'require password change' action is enforced.
Question
Hotspot Question You have a Microsoft Entra tenant that contains the users shown in the following table. You have a user risk policy that has the following settings:
- Assignments:
o Include: Group1 o Exclude: Group2
- Sign-in risk: Medium and above
- Access controls:
o Grant access: Require password change When the users attempt to sign in, user risk levels are detected as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:
Answer Area
- User1 must change their password during sign in.Yes
- User2 must change their password during sign in.No
- User3 must change their password during sign in.No
Explanation
The question tests understanding of Microsoft Entra ID Protection user risk policy evaluation, specifically how group inclusions/exclusions and risk level conditions determine if a 'require password change' action is enforced.
Approach. To determine the correct answers, we must evaluate each user against the user risk policy's assignment, conditions, and access controls:
-
User1 must change their password during sign in: Yes
- Assignment Check: User1 is a member of Group1 (included) and NOT a member of Group2 (not excluded). Therefore, User1 is in scope for the policy.
- Condition Check: User1's detected user risk level is Medium. The policy condition is 'Medium and above'. User1 meets this condition.
- Policy Application: Since User1 is in scope and meets the condition, the policy's access control 'Require password change' is enforced.
- Correct interaction: Select 'Yes' for User1.
-
User2 must change their password during sign in: No
- Assignment Check: User2 is a member of Group1 (included) AND a member of Group2 (excluded). In Microsoft Entra ID Protection policies, exclusions always take precedence over inclusions. Therefore, User2 is excluded from the policy's scope, regardless of other factors.
- Policy Application: The policy does not apply to User2.
- Correct interaction: Select 'No' for User2.
-
User3 must change their password during sign in: No
- Assignment Check: User3 is NOT a member of Group1 (not included). The policy is assigned only to Group1. Therefore, User3 is not in scope for the policy.
- Policy Application: The policy does not apply to User3.
- Correct interaction: Select 'No' for User3.
Common mistakes.
- common_mistake. Common mistakes stem from misinterpreting policy evaluation logic, specifically:
- Ignoring exclusion precedence: Selecting 'Yes' for User2 would be incorrect. While User2 is in the 'Include' group and has a 'High' risk (which meets 'Medium and above'), their membership in the 'Exclude' group (Group2) means the policy will not apply. Exclusions always override inclusions.
- Misinterpreting inclusion scope: Selecting 'Yes' for User3 would be incorrect. Even though User3 has a 'Medium' risk, the policy is explicitly assigned only to 'Group1'. Since User3 is not a member of Group1, the policy's conditions and controls do not apply to them.
- Incorrectly evaluating risk levels: If a user were included but had a 'Low' risk, selecting 'Yes' would be wrong, as 'Low' does not meet the 'Medium and above' condition.
Concept tested. Microsoft Entra ID Protection user risk policy evaluation, including:
- How policy assignments (include/exclude groups) determine scope.
- The precedence of exclusions over inclusions in policy evaluation.
- How risk level conditions ('Medium and above') are evaluated.
- The application of access controls (e.g., 'Require password change') based on policy triggers.
Topics
Community Discussion
No community discussion yet for this question.