FREE STUDY NOTES · SC-200

Microsoft Entra ID Protection: user risk vs sign-in risk

How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Microsoft Entra ID Protection works out two kinds of risk. Sign-in risk is the probability that a given authentication request wasn’t made by the account owner. User risk is the probability that the account’s credentials are known to an attacker. Full detection details need Microsoft Entra ID P2 (or Microsoft Entra Suite). Without P2, premium detections show only as Additional risk detected.

Risk levels and timing

Risk is rated low, medium or high. Some detections are always high: Leaked credentials (a confirmed match against current password hashes) and Verified threat actor IP. Low-risk detections and users age out after six months. Medium and high stay until they’re remediated or dismissed.

Detection type Time to show in reports Effect
Real-time 5-10 minutes Can be remediated during sign-in by a Conditional Access policy (for example MFA)
Offline Up to 48 hours Evaluated after sign-in; unremediated sign-in risk can raise user risk

Examples to know:

Detection Risk type Calculated Licence
Anonymous IP address Sign-in Real-time Free / P1
Unfamiliar sign-in properties Sign-in Real-time P2
Atypical travel Sign-in Offline P2
Password spray Sign-in Real-time or offline P2 (fires only after a successful credential validation)
Impossible travel, New country, Suspicious inbox forwarding Sign-in Offline P2 plus Defender for Cloud Apps (signals come from Defender for Cloud Apps)
Leaked credentials User Offline Free / P1 (needs password hash sync for on-premises passwords)
Attacker in the Middle User Offline Microsoft 365 E5 with EMS E5
Possible attempt to access Primary Refresh Token User Offline Signal comes from Defender for Endpoint

Atypical travel has a learning period of 14 days or 10 sign-ins, whichever comes first. Unfamiliar sign-in properties is off for at least five days for new users while it learns.

Where to see risk

The reports are under Protection > Identity Protection (Risky users, Risky sign-ins, Risk detections) in the Microsoft Entra admin center. Global Reader is the least-privileged role that can view them. In the Defender portal, filter Incidents & alerts > Alerts by Product name = AAD Identity Protection. Built-in report retention is short (risky sign-ins: 7 days on Free, 30 days on P1, 90 days on P2). For longer retention, a Security Administrator configures diagnostic settings to send RiskyUsers and UserRiskEvents to Log Analytics, storage or Event Hubs. In Log Analytics the tables are AADRiskyUsers and AADUserRiskEvents.

AADUserRiskEvents
| where RiskLevel has "high"
| where RiskState has "atRisk"
| mv-expand ParsedFields = parse_json(AdditionalInfo)
| where ParsedFields has "userAgent"
| extend UserAgent = ParsedFields.Value
| project TimeGenerated, UserDisplayName, RiskLevel, RiskEventType, UserAgent

This query lists high-risk detections that are still at risk (not remediated or dismissed), with the user agent pulled from AdditionalInfo for the investigation.

Risk-based Conditional Access

The legacy user risk and sign-in risk policies in ID Protection were retired on 1 October 2026. Risk policies are now built in Conditional Access by a Conditional Access Administrator. Microsoft recommends:

Users must already be registered for MFA, or they’re blocked and need an administrator. Hybrid users need password writeback to self-remediate.

Common trap: Building risk policies under ID Protection’s own policy pages - those legacy policies retired on 1 October 2026. User risk and sign-in risk policies are now Conditional Access policies, and the two risk conditions shouldn’t be combined in one policy.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes