
Explanation:

Microsoft states that Identity Protection is used to "detect potential vulnerabilities affecting your organization' s identities, configure automated responses, and investigate suspicious actions related to your organization's identities." It evaluates user risk and sign-in risk using detections such as "leaked credentials, anonymous IP address, unfamiliar sign-in properties, [and] impossible travel." These built-in detections confirm that the service can detect whether valid user credentials have been found in public or criminal datasets-commonly referred to as leaked credentials-thereby reducing identity compromise risk.
Identity Protection includes policy controls that "automate the response to detected risks," specifically the User risk policy and Sign-in risk policy. Microsoft describes that these policies can "require password change when user risk is detected" and "require multi-factor authentication when sign-in risk is detected." Therefore, Identity Protection can invoke MFA based on risk as part of Conditional Access-backed risk policies.
However, Identity Protection does not perform group lifecycle management. Microsoft positions group membership automation under Azure AD dynamic groups/Identity Governance, not Identity Protection.
Consequently, adding users to groups based on risk level is not a function of Identity Protection, which focuses on detection, risk evaluation, and policy-driven remediation (e.g., MFA or password reset), not group assignment.