Quiz 9 Question 1 of 20

Microsoft Entra ID Protection reports a 'Leaked credentials' risk detection for a user account. The organization has a Conditional Access policy that requires MFA for medium and high user risk. The compromised user successfully authenticates with MFA and continues working. What additional remediation step should the security team take?

Select an answer to reveal the explanation.

Motivation