Microsoft Entra User Risk vs Sign-in Risk Detections
You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam often traps candidates by listing common sign-in risks (like password spray or anonymous IP) alongside the broader user risk category derived from threat intelligence.
This question tests the classification of Microsoft Entra ID Protection risk detections, specifically distinguishing between user risks and sign-in risks. It establishes that Microsoft Entra threat intelligence is the only option classified as a user risk.
Many learners incorrectly choose 'password spray' because it is a well-known attack vector, failing to recognize that it triggers a sign-in risk event rather than a persistent user risk profile.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra ID Protection classifies risk detections into two categories: User risk and Sign-in risk. A User risk indicates that the user's credentials might be compromised based on historical data or external threats. Microsoft Entra threat intelligence aggregates signals from across the internet to identify users whose accounts have been involved in credential stuffing or breaches, classifying them as having a high user risk.Why the Other Options Are Wrong
Options A, B, and C are all classified as Sign-in risks. Password spray involves multiple login attempts with different usernames and a single password, triggering a sign-in risk for that specific attempt. Anonymous IP addresses and unfamiliar sign-in properties (such as new device locations or times) also trigger sign-in risks because they indicate suspicious activity during a specific authentication event, not necessarily a compromised account history.Community Comment Notes
The community consensus strongly supports answer D. As noted by commenter Obi_Wan_Jacoby, "Let's classify each of the risk detection types... Password spray... is considered a sign-in risk." Another commenter Shingie confirms that "Microsoft Entra threat intelligence is classified as a user risk because" it reflects compromised credentials identified through broad intelligence.Exam Strategy
Memorize the distinction: User Risk = Compromised Account History/Threat Intel; Sign-in Risk = Suspicious Activity at Time of Login (Anonymous IP, New Location, Impossible Travel).
Frequently Asked Questions
Is password spray a user risk?
No, password spray is classified as a sign-in risk because it relates to a specific authentication attempt rather than the user's overall account compromise status.
What triggers a user risk score?
User risk scores are primarily triggered by Microsoft Entra threat intelligence detecting that an account's credentials have appeared in known breaches or malicious lists.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →