Continue your lesson
Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.
Block 1 of 3Compare User risk · Sign-in risk · Identity Protection risk policy
Current · 12 min
Compare User risk · Sign-in risk · Identity Protection risk policy
Optional concept notes
User risk
Estimates the likelihood that an identity itself has been compromised.
Sign-in risk
Estimates the likelihood that a specific authentication request is not legitimate.
Identity Protection risk policy
Requires a response such as secure password change or MFA at a selected risk level.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 3Compare Identity Protection risk detection · Risky user remediation · Confirm user compromised · Risky sign-in investigation
18 min
Compare Identity Protection risk detection · Risky user remediation · Confirm user compromised · Risky sign-in investigation
Optional concept notes
Risky user remediation
Lets a user or administrator resolve confirmed identity risk through supported actions.
Identity Protection risk detection
Records the observed signal that contributed to user or sign-in risk.
Confirm user compromised
Marks a risky identity as compromised so response workflows can act on that state.
Risky sign-in investigation
Correlates authentication details detections location device and remediation status.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 3Understand Risky workload identity
15 min
Understand Risky workload identity
Optional concept notes
Risky workload identity
Identifies suspicious service-principal behavior that may indicate application identity compromise.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 2.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.