SC-300 Practice Question 3433
Exam: SC-300
Domain: Implement authentication and access management
Difficulty: hard
You need to create a Conditional Access policy that enforces a password change via SSPR whenever Microsoft Entra Identity Protection flags an account with High User Risk. Which control should you configure in the policy?
Answer Options
A
Require password change (with MFA) in Conditional Access Grant controls
B
Block all access permanently with no self-service remediation
C
Send an email notification to the user personal address
D
Wipe corporate data from user mobile devices
Correct Answer
A: Require password change (with MFA) in Conditional Access Grant controls
Explanation
In the Conditional Access Grant controls, select "Require password change" (which automatically requires MFA) to allow the user to remediate high user risk securely.