Microsoft Entra User Risk vs Sign-in Risk Detections

Manage risk by using Microsoft Entra ID Protection
Answer Correct answer: D — Microsoft Entra threat intelligence is classified as a user risk because it indicates potentially compromised credentials based on external signals.

You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?

  1. password spray
  2. anonymous IP address
  3. unfamiliar sign-in properties
  4. Microsoft Entra threat intelligence Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam often traps candidates by listing common sign-in risks (like password spray or anonymous IP) alongside the broader user risk category derived from threat intelligence.

This question tests the classification of Microsoft Entra ID Protection risk detections, specifically distinguishing between user risks and sign-in risks. It establishes that Microsoft Entra threat intelligence is the only option classified as a user risk.

Many learners incorrectly choose 'password spray' because it is a well-known attack vector, failing to recognize that it triggers a sign-in risk event rather than a persistent user risk profile.

Community Discussion (3 comments)

Obi_Wan_Jacoby 👍 1 Selected: D
Agree with others, answer D: Let's classify each of the risk detection types: Sign-in Risk: A. Password spray: This is considered a sign-in risk. It involves multiple attempts to sign in using common passwords, indicating a potential attack. B. Anonymous IP address: This is also a sign-in risk. It indicates that the sign-in attempt is coming from an IP address that is anonymized, which can be suspicious. C. Unfamiliar sign-in properties: This is a sign-in risk as well. It indicates that the sign-in attempt is coming from an unusual location or device for the user. User Risk: Microsoft Entra threat intelligence: This is classified as a user risk. It indicates that there is suspicious or anomalous activity related to the user account.
59e8fdb 👍 1 Selected: D
REPEATED!
Shingie 👍 1 Selected: D
Correct Answer: ✅ D. Microsoft Entra threat intelligence Explanation: Risk detections in Microsoft Entra ID are classified into two main categories: User risk – Indicates that the user's credentials might be compromised. Sign-in risk – Indicates that a specific sign-in attempt might be suspicious. Among the options provided, Microsoft Entra threat intelligence is classified as a user risk because it detects compromised accounts based on data from internal and external security sources.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra ID Protection classifies risk detections into two categories: User risk and Sign-in risk. A User risk indicates that the user's credentials might be compromised based on historical data or external threats. Microsoft Entra threat intelligence aggregates signals from across the internet to identify users whose accounts have been involved in credential stuffing or breaches, classifying them as having a high user risk.

Why the Other Options Are Wrong

Options A, B, and C are all classified as Sign-in risks. Password spray involves multiple login attempts with different usernames and a single password, triggering a sign-in risk for that specific attempt. Anonymous IP addresses and unfamiliar sign-in properties (such as new device locations or times) also trigger sign-in risks because they indicate suspicious activity during a specific authentication event, not necessarily a compromised account history.

Community Comment Notes

The community consensus strongly supports answer D. As noted by commenter Obi_Wan_Jacoby, "Let's classify each of the risk detection types... Password spray... is considered a sign-in risk." Another commenter Shingie confirms that "Microsoft Entra threat intelligence is classified as a user risk because" it reflects compromised credentials identified through broad intelligence.

Exam Strategy

Memorize the distinction: User Risk = Compromised Account History/Threat Intel; Sign-in Risk = Suspicious Activity at Time of Login (Anonymous IP, New Location, Impossible Travel).

Frequently Asked Questions

Is password spray a user risk?

No, password spray is classified as a sign-in risk because it relates to a specific authentication attempt rather than the user's overall account compromise status.

What triggers a user risk score?

User risk scores are primarily triggered by Microsoft Entra threat intelligence detecting that an account's credentials have appeared in known breaches or malicious lists.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide