
Explanation:
Azure AD Identity Protection (now part of Microsoft Entra ID) is the Microsoft service that "automates the detection and remediation of identity-based risks." It continuously evaluates user risk and sign-in risk using signals such as leaked credentials, atypical travel, unfamiliar sign-in properties, and malware-linked IPs.
Microsoft documentation clarifies that Identity Protection "uses adaptive machine learning and heuristics to detect risky behaviors and sign-ins" and enables administrators to configure risk-based policies (for example, require MFA or block access) to automatically respond. It also provides rich investigations through risk reports so security teams can triage and remediate compromised identities. This distinctly differs from other Entra capabilities: Privileged Identity Management (PIM) governs just-in-time privileged access and role activation, while MFA is an authentication method enforced by policies. Because the service that specifically detects risk and applies automated protection based on risk is Azure AD Identity Protection, it is the correct completion for the sentence about identity risk detection and remediation.