When ID Protection in Microsoft Entra notices something suspicious about an account or a sign-in, for instance credentials found leaked online or a connection through an anonymising IP address, it logs that one event as a detection. These detections add up to an overall user risk and sign-in risk.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Risk detection in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Protection
Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Online management group
Workloads that may talk directly to or from the internet, or that need no virtual network at all, go in this management group. It is a sibling of Corp and Local beneath Landing zones.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- User risk
Microsoft Entra ID Protection's assessment of how likely it is that an account has been compromised, for instance because its credentials have leaked. With Microsoft Entra ID P2 it can be used as a condition in Conditional Access.
- Sign-in risk
Microsoft Entra ID Protection's assessment of how likely it is that a given sign-in was not made by the person who owns the account. With Microsoft Entra ID P2 it can be used as a condition in Conditional Access.