nerdexam
Microsoft

SC-300 · Question #65

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection enabled. You need to implement a sign-in risk remediation policy without blocking user…

The correct answer is D. Implement multi-factor authentication (MFA) for all users. To implement a sign-in risk remediation policy. When a sign in risk policy triggers: Azure AD MFA can be triggered, allowing to user to prove it's them by using one of their registered authentication methods, resetting the sign in risk…

Submitted by luis.pe· Mar 6, 2026Implement authentication and access management

Question

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection enabled. You need to implement a sign-in risk remediation policy without blocking user access. What should you do first?

Options

  • AConfigure access reviews in Azure AD.
  • BEnforce Azure AD Password Protection.
  • CConfigure self-service password reset (SSPR) for all users.
  • DImplement multi-factor authentication (MFA) for all users.

How the community answered

(55 responses)
  • A
    7% (4)
  • B
    11% (6)
  • C
    4% (2)
  • D
    78% (43)

Explanation

To implement a sign-in risk remediation policy. When a sign in risk policy triggers: Azure AD MFA can be triggered, allowing to user to prove it's them by using one of their registered authentication methods, resetting the sign in risk. https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity- protection-configure-risk-policies

Topics

#sign-in risk policy#Identity Protection#MFA#risk remediation

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice