AB-650 Practice Question 3132
Exam: AB-650
Domain: Govern and secure Microsoft 365 tenants and workloads
Difficulty: hard
You need to ensure that when a user's risk level reaches "High" in Microsoft Entra Identity Protection, the account is not locked out, but the user is forced to perform a secure self-service password reset using MFA. Which policy should you configure?
Answer Options
A
User Risk Policy requiring MFA and password change
B
Sign-in Risk Policy blocking domain controllers
C
Exchange anti-spam notification policy
D
Intune remote wipe policy
Correct Answer
A: User Risk Policy requiring MFA and password change
Explanation
A User Risk Policy configured with a Grant control requiring MFA and a password reset allows compromised users to securely remediate their risk independently.