Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
Also called formerly Identity Protection, AAD Identity Protection, ID Protection.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra ID Protection in context, with comparison tables and the common traps.
Terms in this definition
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Microsoft Entra ID P2
Premium licence tier for Microsoft Entra ID that brings ID Protection, which Conditional Access needs for risk-based rules.
- Licence
What entitles one particular user to the services a subscription offers. Each product licence is made up of several service plans (one per app or service), and before giving it to someone an admin has to record that user's usage location.
Related terms
- AADRiskyUsers
A Log Analytics table listing the users that Microsoft Entra ID Protection flags as risky, with each user's risk level and state. It is populated once you export the RiskyUsers category through diagnostic settings.
- AADUserRiskEvents
A Log Analytics table recording the user risk detections raised by Microsoft Entra ID Protection. Data arrives once the UserRiskEvents category is exported through diagnostic settings.
- Agent risk
Condition in Conditional Access based on the risk level Microsoft Entra ID Protection assigns to agent identities, letting a policy stop high-risk agents from obtaining tokens.
- Anonymous IP address
Sign-in risk detection in Microsoft Entra ID Protection, raised when someone signs in through an anonymising proxy like Tor.
- Attacker in the Middle
Also called adversary in the middle (AiTM). Microsoft Entra ID Protection flags this offline when a session is linked to a malicious reverse proxy that can steal tokens and credentials; user risk goes to high, and changing the password won't remediate it automatically.
- Impossible travel
A sign-in risk detection in ID Protection that flags sign-ins from far-apart places made in less time than the journey between them would take.
- Leaked credentials
User risk detection in Microsoft Entra ID Protection, raised when valid credentials turn up on the dark web or in public. It is always classified as high risk.
- MFA registration policy
A Microsoft Entra ID Protection policy that asks targeted users to set up MFA the next time they sign in interactively, allowing 14 days before it is enforced. It requires P2 or Microsoft Entra Suite, and it does not demand MFA on every sign-in.