An account flagged as possibly compromised by ID Protection in Microsoft Entra, typically because of suspicious sign-ins or credentials found leaked. Admins can review these accounts in a dedicated report.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Risky user in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Protection
Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
Related terms
- Insider Risk Management
A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
- Require risk remediation
Leaves it to ID Protection to decide how a risky user is fixed, either reauthentication or a secure password change, regardless of how they sign in. Selecting it also adds sign-in frequency set to Every time and an authentication strength.