A security engineer is implementing Microsoft Entra ID Protection for a financial institution. The engineer needs to configure the user risk remediation to allow users to self-remediate high user risk by performing password reset and MFA, rather than requiring IT helpdesk involvement. What must be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a Conditional Access user risk policy configured to grant access with 'Require password change' as the grant control for high user risk allows self-remediation: the user is required to perform an MFA challenge and then reset their password, which automatically remediates the user risk without IT intervention. A is incorrect because blocking high-risk users prevents access but does not enable self-remediation; users must contact IT.
Full explanation below image
Full Explanation
B is correct because a Conditional Access user risk policy configured to grant access with 'Require password change' as the grant control for high user risk allows self-remediation: the user is required to perform an MFA challenge and then reset their password, which automatically remediates the user risk without IT intervention. A is incorrect because blocking high-risk users prevents access but does not enable self-remediation; users must contact IT. C is incorrect because a sign-in risk policy addresses individual sign-in events, not accumulated user risk, and MFA alone does not remediate user risk (password change is required). D is incorrect because auto-dismissal of risk detections without remediation is a security gap, not a self-remediation mechanism.