Microsoft Entra ID Protection's assessment of how likely it is that an account has been compromised, for instance because its credentials have leaked. With Microsoft Entra ID P2 it can be used as a condition in Conditional Access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains User risk in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Protection
Uses risk scores on users and sign-ins to spot, look into and fix threats to identities. Policies that respond to that risk live in Conditional Access, and a Microsoft Entra ID P2 licence is required.
- Microsoft Entra ID P2
Premium licence tier for Microsoft Entra ID that brings ID Protection, which Conditional Access needs for risk-based rules.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- AADUserRiskEvents
A Log Analytics table recording the user risk detections raised by Microsoft Entra ID Protection. Data arrives once the UserRiskEvents category is exported through diagnostic settings.
- Attacker in the Middle
Also called adversary in the middle (AiTM). Microsoft Entra ID Protection flags this offline when a session is linked to a malicious reverse proxy that can steal tokens and credentials; user risk goes to high, and changing the password won't remediate it automatically.
- CAE
Instead of letting an access token run until it expires, Microsoft Entra continuous access evaluation allows Microsoft Graph, Teams, SharePoint Online, Exchange Online and similar services to end a session almost straight away. Triggers include a disabled account, a password reset, revoked tokens, high user risk or a move to a different network location.
- Entra ID Protection
Calculates sign-in risk and user risk and enforces the MFA registration policy; it comes with Entra ID P2.
- Leaked credentials
User risk detection in Microsoft Entra ID Protection, raised when valid credentials turn up on the dark web or in public. It is always classified as high risk.
- Report suspicious activity
If an MFA prompt arrives that someone didn't trigger, they can flag it; ID Protection then treats them as high user risk and remediation follows. This replaced fraud alert, which went away on 1 March 2025.
- Risk detection
When ID Protection in Microsoft Entra notices something suspicious about an account or a sign-in, for instance credentials found leaked online or a connection through an anonymising IP address, it logs that one event as a detection. These detections add up to an overall user risk and sign-in risk.