How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
Microsoft Entra ID Protection works out two kinds of risk. Sign-in risk is the probability that a given authentication request wasn’t made by the account owner. User risk is the probability that the account’s credentials are known to an attacker. Full detection details need Microsoft Entra ID P2 (or Microsoft Entra Suite). Without P2, premium detections show only as Additional risk detected.
Risk is rated low, medium or high. Some detections are always high: Leaked credentials (a confirmed match against current password hashes) and Verified threat actor IP. Low-risk detections and users age out after six months. Medium and high stay until they’re remediated or dismissed.
| Detection type | Time to show in reports | Effect |
|---|---|---|
| Real-time | 5-10 minutes | Can be remediated during sign-in by a Conditional Access policy (for example MFA) |
| Offline | Up to 48 hours | Evaluated after sign-in; unremediated sign-in risk can raise user risk |
Examples to know:
| Detection | Risk type | Calculated | Licence |
|---|---|---|---|
| Anonymous IP address | Sign-in | Real-time | Free / P1 |
| Unfamiliar sign-in properties | Sign-in | Real-time | P2 |
| Atypical travel | Sign-in | Offline | P2 |
| Password spray | Sign-in | Real-time or offline | P2 (fires only after a successful credential validation) |
| Impossible travel, New country, Suspicious inbox forwarding | Sign-in | Offline | P2 plus Defender for Cloud Apps (signals come from Defender for Cloud Apps) |
| Leaked credentials | User | Offline | Free / P1 (needs password hash sync for on-premises passwords) |
| Attacker in the Middle | User | Offline | Microsoft 365 E5 with EMS E5 |
| Possible attempt to access Primary Refresh Token | User | Offline | Signal comes from Defender for Endpoint |
Atypical travel has a learning period of 14 days or 10 sign-ins, whichever comes first. Unfamiliar sign-in properties is off for at least five days for new users while it learns.
The reports are under Protection > Identity Protection (Risky users, Risky sign-ins, Risk detections) in the Microsoft Entra admin center. Global Reader is the least-privileged role that can view them. In the Defender portal, filter Incidents & alerts > Alerts by Product name = AAD Identity Protection. Built-in report retention is short (risky sign-ins: 7 days on Free, 30 days on P1, 90 days on P2). For longer retention, a Security Administrator configures diagnostic settings to send RiskyUsers and UserRiskEvents to Log Analytics, storage or Event Hubs. In Log Analytics the tables are AADRiskyUsers and AADUserRiskEvents.
AADUserRiskEvents
| where RiskLevel has "high"
| where RiskState has "atRisk"
| mv-expand ParsedFields = parse_json(AdditionalInfo)
| where ParsedFields has "userAgent"
| extend UserAgent = ParsedFields.Value
| project TimeGenerated, UserDisplayName, RiskLevel, RiskEventType, UserAgent
This query lists high-risk detections that are still at risk (not remediated or dismissed), with the user agent pulled from AdditionalInfo for the investigation.
The legacy user risk and sign-in risk policies in ID Protection were retired on 1 October 2026. Risk policies are now built in Conditional Access by a Conditional Access Administrator. Microsoft recommends:
Users must already be registered for MFA, or they’re blocked and need an administrator. Hybrid users need password writeback to self-remediate.
Common trap: Building risk policies under ID Protection’s own policy pages - those legacy policies retired on 1 October 2026. User risk and sign-in risk policies are now Conditional Access policies, and the two risk conditions shouldn’t be combined in one policy.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.