An organization is using Microsoft Entra ID Protection and has configured risk policies. A user's sign-in attempt is flagged with a high 'sign-in risk', but their overall 'user risk' level remains low. Which of the following events would MOST likely trigger a high sign-in risk without immediately elevating the user risk?
-
A
The user successfully signs in from a new country while on vacation.
-
B
The user's password was discovered in a public data breach from another service.
-
C
A sign-in is attempted from an IP address associated with a TOR browser.
-
D
The user repeatedly fails multi-factor authentication prompts over several hours.