AB-650 Practice Question 3132

Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: hard
You need to ensure that when a user's risk level reaches "High" in Microsoft Entra Identity Protection, the account is not locked out, but the user is forced to perform a secure self-service password reset using MFA. Which policy should you configure?

Answer Options

A
User Risk Policy requiring MFA and password change
B
Sign-in Risk Policy blocking domain controllers
C
Exchange anti-spam notification policy
D
Intune remote wipe policy

Correct Answer

A: User Risk Policy requiring MFA and password change

Explanation

A User Risk Policy configured with a Grant control requiring MFA and a password reset allows compromised users to securely remediate their risk independently.