SC-300 · Question #325
You have a Microsoft Entra tenant. You need to query risky user activity for the tenant. How long will the logs of risky user activity be retained?
The correct answer is C. 90 days. Explanation Microsoft Entra ID (formerly Azure AD) retains risky user activity logs - including sign-in risk and user risk data from Identity Protection - for 90 days, making option C correct. This 90-day retention period applies to the risky users report, risky sign-ins…
Question
You have a Microsoft Entra tenant. You need to query risky user activity for the tenant. How long will the logs of risky user activity be retained?
Options
- A30 days
- B60 days
- C90 days
- D180 days
How the community answered
(53 responses)- A2% (1)
- B4% (2)
- C94% (50)
Explanation
Explanation
Microsoft Entra ID (formerly Azure AD) retains risky user activity logs - including sign-in risk and user risk data from Identity Protection - for 90 days, making option C correct. This 90-day retention period applies to the risky users report, risky sign-ins report, and risk detections available in the Microsoft Entra portal.
- Option A (30 days) is incorrect; this is a common distractor often confused with the standard sign-in log retention for free-tier Microsoft Entra tenants.
- Option B (60 days) is incorrect; this duration does not correspond to any standard Microsoft Entra log retention period.
- Option D (180 days) is incorrect; while longer retention periods can be achieved by exporting logs to external storage (e.g., Azure Monitor or a SIEM), the native retention within the portal is not 180 days.
Memory Tip: Think of "90 days = 3 months of risk" - Identity Protection needs a full quarter of data to assess meaningful risk trends, which makes 90 days logical and easy to remember for exam purposes.
Topics
Community Discussion
No community discussion yet for this question.