How Long Are Microsoft Entra Risky User Activity Logs Retained?
You have a Microsoft Entra tenant. You need to query risky user activity for the tenant. How long will the logs of risky user activity be retained?
Community Votes
57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the Identity Protection risk-data retention window by license tier; the trap is confusing the never-deleted risky users list with the queryable risk log window (90 days on P2 versus 30 days on P1).
Microsoft Entra Identity Protection retains queryable risky user activity data for 90 days, which is the retention window this SC-300 question targets. The page explains why 90 days (C) beats the tempting 30-day option and how the community reached that verdict.
Choosing 30 days (A) because the risky sign-ins report defaults to 30 days on P1, or because candidates mix up the risky users list — which Microsoft says is not deleted until risk is remediated — with the actual log retention period the question asks about.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Within Microsoft Entra Identity Protection, the risk data you query for triage — risk detections and risky sign-in activity — is retained on a rolling window that reaches 90 days for the premium Identity Protection tiers, which is why the SC-300 key and the larger share of voters land on option C. The question asks how long risky user activity logs are retained for querying, i.e. the reportable retention window rather than how long a user object stays flagged. Nail confirmed this directly from the product: "I can go back a maximum of 90 days" while browsing Identity Protection > Report > Risky Users, and added that the question implicitly assumes a P2 tenant. Btn26 makes the same licensing link, noting Identity Protection is a P2 feature and that P2 carries 90-day retention for risky sign-in data. Read together with Microsoft's report-retention reference, 90 days is the defensible exam answer here.Why the Other Options Are Wrong
Option A (30 days) is the retention figure learners most often anchor to, but it corresponds to the shorter tier of the risky sign-ins report rather than the full Identity Protection query window — it is the classic P1-versus-P2 distractor. Sozo and rvln7 both argued 30 days by pointing at the risky sign-ins report text that says filterable data covers up to the past 30 days, but that sentence describes the free/P1 default, not the retention the exam is asking about. B and D (60 and 180 days) appear in no Microsoft retention table for Identity Protection reports, so they can be eliminated on sight. The nuance that trips people up is that a privileged user can also retain data longer by exporting it, but that is a customer configuration, not the service retention period.Community Comment Notes
Opinion was genuinely split (C 53 votes versus A 40), and throwaway10188 pointed out that Microsoft's retention reference table shows risky users with no limit because "Risky users and workload identities are not deleted until the risk has been remediated" — a fair objection to the wording, not to the retention window the exam tests. Tony416 supplied the SC-300 Exam Prep heuristic: risky sign-in activity follows sign-in log rotation (roughly 30 days, the A trap) while risk detections rotate at 90 days. baz cited the risk report documentation for the 30-day figure, and d1e85d9 posted confirmation for 90 days with the investigate-risk Learn page. Overall the thread supports 90 days as the intended exam answer, with the caveat that the question's phrasing about "logs" is loose.Official Reference
Exam Strategy
Memorize the tiering: risky sign-ins follow sign-in log rotation (about 30 days on lower tiers, up to 90 with Identity Protection), risk detections rotate at 90 days, and the risky users list itself does not expire until remediated. When an SC-300 question asks how long you can query or report on risk activity, the 90-day P2 window is the expected figure.
Frequently Asked Questions
Why is 30 days (A) wrong if the risky sign-ins report shows 30 days of data?
The 30-day figure is the shorter retention tier tied to sign-in log rotation on lower license levels; the Identity Protection risk data the question targets is retained for 90 days.
Do risky users expire, or is that a different retention rule?
Risky users and workload identities are not deleted until the risk is remediated, but the queryable activity logs used for triage follow the 90-day retention window.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →