The low, medium or high value that Microsoft Entra ID Protection gives to show how likely it is that an account or a sign-in has been compromised; Conditional Access policies based on risk respond to it. Insider risk levels in Microsoft Purview Adaptive Protection (Elevated, Moderate, Minor) are a different scale.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Risk level in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Protection
Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- Insider risk
Lets Conditional Access react to the risk level that Adaptive Protection in Microsoft Purview gives a user (minor, moderate or elevated), blocking them or asking for stronger controls.
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
Related terms
- AADRiskyUsers
A Log Analytics table listing the users that Microsoft Entra ID Protection flags as risky, with each user's risk level and state. It is populated once you export the RiskyUsers category through diagnostic settings.
- Agent risk
Condition in Conditional Access based on the risk level Microsoft Entra ID Protection assigns to agent identities, letting a policy stop high-risk agents from obtaining tokens.