SC-300 Exam QuestionsBrowse all questions from this exam

SC-300 Exam - Question 297


HOTSPOT -

You need to meet the technical requirements for the probability that user identities were compromised.

What should the users do first, and what should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Show Answer
Correct Answer:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies

Discussion

17 comments
Sign in to comment
DPRamone
May 28, 2021

IMO, you would need to set up MFA before SSPR when as per requirement protecting against leaked credentials by implementing a sign-in risk remediation policy without blocking access. Ref. https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identityprotection-remediate-unblock .

007Ali
Jan 10, 2022

I agree that in reality, you would enable MFA as that is the best way to protect accounts, but I think this question is about setting up a User Risk Policy, and in that policy one of the settings is "Identity Protection -> User Risk Policy -> Controls -> Allow access -> Require password change". Therefore setting up SSPR is required to complete this task.

densyo
Sep 28, 2021

The answers are correct. The question is about probability that user identities were compromised User risk is a calculation of probability that an "identity" has been compromised. Administrators can choose to block access, allow access, or allow access but require a password change using Azure AD self-service password reset.

Borbz
Nov 24, 2021

You are correct.

Faheem2020
Oct 4, 2022

MFA and user risk policy is the answer for me. "When a user risk policy triggers: Administrators can require a secure password reset, requiring Azure AD MFA be done before the user creates a new password with SSPR, resetting the user risk." https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies

RandomNickname
Jun 21, 2022

MFA is a requirement for enabling SSPR and there's no mention in the Introductory Info that MFA is already setup. See below URL for reference; https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr So for me it's MFA and User Risk Pol

w00t
Sep 12, 2022

It's User Risk and SSPR Within a User Risk policy, when setting the Controls - Access section, you only have two options: 1) you completely block the user 2) you allow the user access still, but they "Require password change" MFA would be related to Sign-In risk policy, not User Risk.

Jun143
Mar 21, 2022

just pass the exam today. This came in the question. MFA + User Risk Policy

sapien45
Jun 29, 2022

MFA ans SSPR are two duistincts setups that look similar and therefore lots of people are getting confused. That is why Azure is now forccing the combined setup : Before combined registration, users registered authentication methods for Azure AD Multi-Factor Authentication and self-service password reset (SSPR) separately. People were confused that similar methods were used for Multi-Factor Authentication and SSPR but they had to register for both features. Now, with combined registration, users can register once and get the benefits of both Multi-Factor Authentication and SSPR. https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined But since there is no mention of cpmbined setup SSPR it is

wsrudmen
Jan 26, 2023

It's really hard to say. The Microsoft says the pros and cons. "To perform secure password change to self-remediate a user risk: The user must have registered for Azure AD MFA." and after some lines " Self-remediation with self-service password reset If a user has registered for self-service password reset (SSPR), then they can also remediate their own user risk by performing a self-service password reset." https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-remediate-unblock

stromnessian
Mar 10, 2022

Require the user to reset password - Requiring the users to reset passwords enables self-recovery without contacting help desk or an administrator. This method only applies to users that are registered for Azure AD MFA and SSPR. For users that haven't been registered, this option isn't available.

Xyz_40
Jun 19, 2022

Users-risky situation. Users must first have SSPR enabled first. And then you will need to configure User-risk policy

Sneekygeek
Jan 30, 2024

In the requirements: Users must be forced to change their password if there is a probability that the users' identity was compromised. You would need to register users for SSPR first and then create a user-risk policy that forces them to change their password.

stromnessian
Mar 10, 2022

Yes, correct.

TheGuy
Mar 13, 2022

IMO, it is SSPR since MFA is not one of the requirements making me assuming MFA is already enabled. Also, in order to automate a password reset, SSPR needs to be enabled when the risky-user policy kicks in.

Yelad
Mar 30, 2022

On the exam - March 28, 2022

Faheem2020
Aug 29, 2022

MFA is a requirement here.

dule27
Jul 4, 2023

SSPR A user risk policy

thetootall
Jul 18, 2024

On exam 7/18/24, used answered provided In the requirements: Users must be forced to change their password if there is a probability that the users' identity was compromised. You would need to register users for SSPR first and then create a user-risk policy that forces them to change their password.