SC-300 Practice Question 3433

Exam: SC-300
Domain: Implement authentication and access management
Difficulty: hard
You need to create a Conditional Access policy that enforces a password change via SSPR whenever Microsoft Entra Identity Protection flags an account with High User Risk. Which control should you configure in the policy?

Answer Options

A
Require password change (with MFA) in Conditional Access Grant controls
B
Block all access permanently with no self-service remediation
C
Send an email notification to the user personal address
D
Wipe corporate data from user mobile devices

Correct Answer

A: Require password change (with MFA) in Conditional Access Grant controls

Explanation

In the Conditional Access Grant controls, select "Require password change" (which automatically requires MFA) to allow the user to remediate high user risk securely.