Microsoft Entra ID Protection's assessment of how likely it is that a given sign-in was not made by the person who owns the account. With Microsoft Entra ID P2 it can be used as a condition in Conditional Access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Sign-in risk in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Protection
Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
- Microsoft Entra ID P2
Premium licence tier for Microsoft Entra ID that brings ID Protection, which Conditional Access needs for risk-based rules.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- Anonymous IP address
Sign-in risk detection in Microsoft Entra ID Protection, raised when someone signs in through an anonymising proxy like Tor.
- Entra ID Protection
Calculates sign-in risk and user risk and enforces the MFA registration policy; it comes with Entra ID P2.
- Impossible travel
A sign-in risk detection in ID Protection that flags sign-ins from far-apart places made in less time than the journey between them would take.
- Risk detection
When ID Protection in Microsoft Entra notices something suspicious about an account or a sign-in, for instance credentials found leaked online or a connection through an anonymising IP address, it logs that one event as a detection. These detections add up to an overall user risk and sign-in risk.
- Unfamiliar sign-in location
A sign-in risk detection in ID Protection raised when the location, IP address or device has not previously been seen for that user.