Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
01Microsoft Defender XDR6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps0/53 units complete
Learning path 01 · Microsoft Defender XDR

6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps

0%

Study focus

Incident operations

Correlate, investigate, hunt, and remediate threats across Defender XDR.

Domain protection

Protect email, identities, Active Directory, cloud apps, and sensitive data.

6 modules · 53 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

04

Module 4

Manage Microsoft Entra Identity Protection

Focus: identity risk detection, risk-based Conditional Access, MFA registration, risky-user investigation, workload identities, and identity-risk agents.
0/11
01 / 11Introduction

Identity Protection analyzes user behavior and sign-in patterns to detect identity risk. The module covers risk detections, user and sign-in risk policies, MFA registration, investigation, workload identities, Defender for Identity, and the Identity Risk Management Agent.

Official lesson + embedded videoIdentity Protection overview
02 / 11Review Identity Protection basics

Identity Protection automates detection/remediation, supports portal investigation, and exports risk data to SIEM and third-party tools. Full capabilities require Microsoft Entra ID Premium P2.

Risk detectionMeaning
Anonymous or malicious IPSign-in from anonymizers or known malicious infrastructure
Atypical travel / unfamiliar propertiesSign-in differs from the user's normal location, device, browser, or network
Leaked credentials / password sprayCredentials exposed or common passwords tried across accounts
Anomalous token / issuer anomalySuspicious token properties, replay, or SAML issuer behavior
Threat intelligenceActivity matches known Microsoft threat patterns or actors

Security Administrator has broad Identity Protection access; Security Operator can investigate and confirm safe/compromised activity but cannot configure policies or reset passwords; Security Reader is read-only.

Exam takeaway: risk signals feed Conditional Access decisions; P2 unlocks risk policies and full reports.
Official lessonRisks, roles, and licensing
03 / 11Implement and manage user risk policy
  • Sign-in risk estimates whether a specific authentication was performed by someone other than the legitimate user.
  • User risk estimates whether the account itself is compromised.

For self-remediation, users must be registered for MFA and SSPR. Microsoft recommends a user-risk threshold of High and a sign-in-risk threshold of Medium and above. Exclude emergency access accounts and review exclusions regularly.

Official lesson + embedded videoRisk policy design and rollout
04 / 11Exercise: enable risk policies
User riskHigh risk → require secure password change.
Sign-in riskMedium and above → require MFA.
AssignmentsScope users/groups and exclude emergency accounts.
DeploymentTest, enable, monitor, and tune.

Use the Entra admin center under Identity → Protection → Identity Protection. The lesson UI also shows block controls, but Microsoft's self-remediation recommendation is to allow access with password change for user risk and MFA for sign-in risk.

05 / 11Exercise: MFA registration policy

MFA registration policy ensures users register a second authentication factor before a risky event occurs. Under Identity Protection, assign users/groups, retain the fixed control Require Microsoft Entra ID multifactor authentication registration, enable the policy, and save.

Exam takeaway: registration is a prerequisite for users to satisfy MFA and self-remediate risk.
Official exerciseMFA registration policy
06 / 11Monitor, investigate, and remediate risky users
ReportPurposeRetention shown
Risky usersUser risk state, history, detections, and remediationCurrent/history view
Risky sign-insRisk, Conditional Access, MFA, device, app, and locationUp to 30 days
Risk detectionsIndividual detection types, location, and related risksUp to 90 days

Remediation options include policy-based self-remediation, password reset, confirming compromise/safety, dismissing risk, blocking sign-in, or closing individual detections. Dismissing risk closes events but does not change an exposed password, so use it only when the risk is known to be false or otherwise handled.

Exam takeaway: MFA + SSPR enable self-remediation; investigate before dismissing risk.
Official lessonReports, investigation, remediation, and Graph APIs
07 / 11Implement security for workload identities

Workload identities represent applications, service principals, and managed identities. They cannot perform MFA, often lack lifecycle governance, and must store credentials, which increases risk.

  • Risk detections include threat-intelligence matches, suspicious sign-ins, unusual OAuth credential additions, admin-confirmed compromise, and leaked credentials.
  • Requires Entra ID Premium P2 and a Security Administrator, Operator, or Reader role.
  • Conditional Access for workload identities can block risky single-tenant service principals; multi-tenant apps, third-party SaaS, and managed identities are outside that policy scope.
Official lessonWorkload identity risk
08 / 11Explore Microsoft Defender for Identity

Defender for Identity uses on-premises Active Directory signals to detect compromised identities and insider threats. Sensors installed on domain controllers and AD FS observe traffic and authentication events, send parsed data to the cloud service, and surface incidents in the Defender portal.

Official lessonMDI process flow and components
09 / 11Explore the Identity Risk Management Agent

The Security Copilot agent scans at-risk users, investigates risky sign-ins and detections, generates a risk summary and verdict, and suggests remediation such as dismissing risk or resetting a password.

  • Requires Entra ID P2, Security Compute Units, and appropriate roles.
  • Triggers: continuous (every five minutes), daily, or manual.
  • Scope: selected users/groups, risk level, up to 100 recent risky users, and up to 90 days.
  • Security Reader/Global Reader can view; Security Administrator activates and takes action.
Exam takeaway: agent suggestions accelerate review but remain governed by scope, permissions, and analyst action.
Official lessonIdentity Risk Management Agent
10 / 11Module assessment
Security Operator task → Confirm safe sign-in
Second directory risk policy → Sign-in risk policy
Graph APIs → riskDetection, riskyUsers, signIns
Official assessmentThree questions
11 / 11Summary and resources

Review risk policies, combined MFA/SSPR registration, emergency access accounts, managed identities, risk remediation, notifications, and Defender for Identity.

Official summaryEight linked Microsoft resources
End of learning pathMicrosoft Defender XDR