Exam objective

SC-300

Manage risk by using Microsoft Entra ID Protection

This objective sits in Implement authentication and access management, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement authentication and access management

An admin at a company wants a Conditional Access policy that blocks access when a sign-in is calculated as risky and when a user account itself is flagged as risky. Which license enables this risk-based signal?

A Microsoft Entra ID P1 license assigned to the affected usersP1 licensing enables core Conditional Access policies but not the risk detection signals from ID Protection.
Security defaults enabled for the tenant, no premium licenseSecurity defaults offer baseline protection for all customers but do not support risk-based policy conditions.
A Microsoft 365 Business Premium license for the affected usersBusiness Premium grants some Conditional Access capability but not the P2-tier ID Protection risk signals.
A Microsoft Entra ID P2 license assigned to the affected usersCorrect · your answerThis is correct: risk-based policies require Microsoft Entra ID Protection, a P2 feature.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Risk-based Conditional Access policies (sign-in risk and user risk) depend on Microsoft Entra ID Protection, which is licensed at the P2 tier.

Why D

Only a Microsoft Entra ID P2 license unlocks Microsoft Entra ID Protection, which supplies the sign-in risk and user risk signals that risk-based Conditional Access policies evaluate.

Source

Risk-based Conditional Access policies (sign-in risk and user risk) require Microsoft Entra ID Protection, which is a Microsoft Entra ID P2 feature.

Conditional Access overview, checked July 2026
#identity-protection#conditional-access#licensing#risk

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement authentication and access management

A tenant admin is building a Conditional Access policy that must automatically respond when a user is flagged as risky or a sign-in shows risky behavior, based on ongoing risk analysis rather than in-session activity monitoring. Which common signal category supplies this input?

Sample question 2 of 3

Implement authentication and access management

A tenant administrator wants to build Conditional Access policies that block sign-in attempts based on calculated sign-in risk and user risk levels. Which license tier must be present in the tenant to support these risk-based policies?

Sample question 3 of 3

Implement authentication and access management

A security team configures a Conditional Access policy that grants access only after risky sign-in behavior has been remediated. Which capability supplies the risk signal that this policy evaluates?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement authentication and access management