How Long Are Microsoft Entra Risky User Activity Logs Retained?

Answer Correct answer: C — Microsoft Entra Identity Protection retains queryable risky user activity logs for 90 days, so that is the window available for risk queries.

You have a Microsoft Entra tenant. You need to query risky user activity for the tenant. How long will the logs of risky user activity be retained?

  1. 30 days
  2. 60 days
  3. 90 days Correct Answer
  4. 180 days

Community Votes

C
57%
A
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the Identity Protection risk-data retention window by license tier; the trap is confusing the never-deleted risky users list with the queryable risk log window (90 days on P2 versus 30 days on P1).

Microsoft Entra Identity Protection retains queryable risky user activity data for 90 days, which is the retention window this SC-300 question targets. The page explains why 90 days (C) beats the tempting 30-day option and how the community reached that verdict.

Choosing 30 days (A) because the risky sign-ins report defaults to 30 days on P1, or because candidates mix up the risky users list — which Microsoft says is not deleted until risk is remediated — with the actual log retention period the question asks about.

Community Discussion (15 comments)

d1e85d9 👍 2 Selected: C
C) confirmed 90 Days Ref Link: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#how-to-investigate-risky-users
rvln7 👍 1 Selected: A
This table reflects the latest information on retention periods for Microsoft Entra Free, P1, and P2 as of February 26, 2025. I just had to mark the answer, but as I said...there is no limit for risky users. "Risky users and workload identities are not deleted until the risk has been remediated." ------------------------------------------------- | Feature | Microsoft Entra Free | P1 | P2 | ------------------------------------------------- | Audit Logs | 7 days | 30 days | 30 days | ------------------------------------------------- | Sign-ins | 7 days | 30 days | 30 days | ------------------------------------------------- | Multifactor Authentication Usage | 30 days | 30 days | 30 days | ------------------------------------------------- | Risky Users | No limit | No limit| No limit| ------------------------------------------------- | Risky Sign-ins | 7 days | 30 days | 90 days | -------------------------------------------------
Rahgu 👍 1 Selected: C
It's 90 days, so C.
Btn26 👍 1 Selected: C
Why 90 days is the better answer in this context: The question specifically asks about "risky user activity," implying the use of Identity Protection features. Identity Protection, with its detailed risk assessments and reporting, is a core component of Premium P2. Premium P2 has a 90-day retention for risky sign-ins.
Phax 👍 2
90 days, logs of risky user activity are usually retained for 90 days...
murcao 👍 1
The question is not well done, but considering the maximum time is 90 days (Entra P2) I will select the option C > Microsoft Entra ID Free : 7 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 90 days This retention period allows you to monitor and analyze risky user activity over a significant period to ensure security and compliance More information: Audit logs > Microsoft Entra ID Free: Seven days > Microsoft Entra ID P1: Seven days > Microsoft Entra ID P2: 30 days Sign-ins > Microsoft Entra ID Free: 30 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 30 days Microsoft Entra multifactor authentication usage > Microsoft Entra ID Free: 30 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 30 days Based on the link below: https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention
Nail 👍 4 Selected: C
I'm going with 90. I'm in the portal right now under Identity Protection, Report, Risky Users and I can go back a maximum of 90 days. Almost all of the other questions seem to assume you have P2.
Tony416 👍 3 Selected: A
This is a tip found in the MS Book SC-300 Exam Prep: The risk reports have different log-rotation periods. The Risky Users report tracks risky users since the beginning of time (from the perspective of tenant inception). The Risky Sign-in report tracks with the log rotation period of the sign-in logs (30 days). The Risk Detections report has a log-rotation period of 90 days.
Tony416 👍 1 Selected: D
This question is entirely nonsensical. I found 90 days. There's no reference to 30 days, even though the log time can be changed. https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#how-to-investigate-risky-users "When administrators select an individual user, the Risky user details pane appears. Risky user details provide information like: user ID, office location, recent risky sign-in, detections not linked to a sign, and risk history. The Risk history tab shows the events that led to a user risk change in the last 90 days."
jarattdavis 👍 1
Answer is 90 days. The Risk history tab also shows all the events that led to a user risk change in the last 90 days. This list includes risk detections that increased the user’s risk and admin remediation actions that lowered the user’s risk. Note: Question is not referring to Sign in risk which is 30 days. https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#:~:text=The%20Risk%20history%20tab%20also%20shows%20all%20the%20events%20that%20led%20to%20a%20user%20risk%20change%20in%20the%20last%2090%20days
ELQUMS 👍 2
A - in Exam
Sozo 👍 2 Selected: A
The retention period for logs of risky user activity in Microsoft Entra varies by report type and license type. For instance, the risky sign-ins report contains filterable data for up to the past 30 days. However, you can retain the audit and sign-in activity data for longer than the default retention period by routing it to an Azure storage account using Azure Monitor.
baz 👍 4
A. The risky sign-ins report contains filterable data for up to the past 30 days (one month) https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#risky-users-report
throwaway10188 👍 3
This question is trash. No license specified and even if it did Risky User 'Activity' is retained until the end of time/resolved.
throwaway10188 👍 4
https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention Risky users No limit No limit No limit Risky sign-ins 7 days 30 days 90 days Note Risky users and workload identities are not deleted until the risk has been remediated.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Within Microsoft Entra Identity Protection, the risk data you query for triage — risk detections and risky sign-in activity — is retained on a rolling window that reaches 90 days for the premium Identity Protection tiers, which is why the SC-300 key and the larger share of voters land on option C. The question asks how long risky user activity logs are retained for querying, i.e. the reportable retention window rather than how long a user object stays flagged. Nail confirmed this directly from the product: "I can go back a maximum of 90 days" while browsing Identity Protection > Report > Risky Users, and added that the question implicitly assumes a P2 tenant. Btn26 makes the same licensing link, noting Identity Protection is a P2 feature and that P2 carries 90-day retention for risky sign-in data. Read together with Microsoft's report-retention reference, 90 days is the defensible exam answer here.

Why the Other Options Are Wrong

Option A (30 days) is the retention figure learners most often anchor to, but it corresponds to the shorter tier of the risky sign-ins report rather than the full Identity Protection query window — it is the classic P1-versus-P2 distractor. Sozo and rvln7 both argued 30 days by pointing at the risky sign-ins report text that says filterable data covers up to the past 30 days, but that sentence describes the free/P1 default, not the retention the exam is asking about. B and D (60 and 180 days) appear in no Microsoft retention table for Identity Protection reports, so they can be eliminated on sight. The nuance that trips people up is that a privileged user can also retain data longer by exporting it, but that is a customer configuration, not the service retention period.

Community Comment Notes

Opinion was genuinely split (C 53 votes versus A 40), and throwaway10188 pointed out that Microsoft's retention reference table shows risky users with no limit because "Risky users and workload identities are not deleted until the risk has been remediated" — a fair objection to the wording, not to the retention window the exam tests. Tony416 supplied the SC-300 Exam Prep heuristic: risky sign-in activity follows sign-in log rotation (roughly 30 days, the A trap) while risk detections rotate at 90 days. baz cited the risk report documentation for the 30-day figure, and d1e85d9 posted confirmation for 90 days with the investigate-risk Learn page. Overall the thread supports 90 days as the intended exam answer, with the caveat that the question's phrasing about "logs" is loose.

Official Reference

Exam Strategy

Memorize the tiering: risky sign-ins follow sign-in log rotation (about 30 days on lower tiers, up to 90 with Identity Protection), risk detections rotate at 90 days, and the risky users list itself does not expire until remediated. When an SC-300 question asks how long you can query or report on risk activity, the 90-day P2 window is the expected figure.

Frequently Asked Questions

Why is 30 days (A) wrong if the risky sign-ins report shows 30 days of data?

The 30-day figure is the shorter retention tier tied to sign-in log rotation on lower license levels; the Identity Protection risk data the question targets is retained for 90 days.

Do risky users expire, or is that a different retention rule?

Risky users and workload identities are not deleted until the risk is remediated, but the queryable activity logs used for triage follow the 90-day retention window.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide