FREE STUDY NOTES · SC-300

User risk vs sign-in risk in Microsoft Entra ID Protection

The difference between the two risk types, real-time versus offline detections, and which detections need P2.

From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)

Every detection contributes either to sign-in risk (the probability that a given authentication request isn’t from the account owner) or to user risk (the probability that the identity itself is compromised). Risk is graded low, medium or high, and some detections are calculated in real time while others are calculated offline.

Real-time and offline detections

Aspect Real-time Offline
When calculated During the sign-in After the sign-in
Time to appear in reports 5-10 minutes Up to 48 hours
Sign-in risk effect Can be remediated during the sign-in by a Conditional Access policy (for example, require MFA) Can’t be remediated in that sign-in; unremediated sign-in risk can aggregate into user risk
User risk effect Remediated through a Conditional Access policy, such as a secure password change User is blocked at next sign-in until they remediate, if a policy applies

Low-risk detections and users age out after six months; medium and high risk persist until remediated or dismissed. Leaked credentials and Verified threat actor IP are always high risk. Sign-ins from trusted named locations lower the calculated sign-in risk, which is why corporate egress ranges should be defined as trusted locations.

Detections worth knowing

Detection Risk type Calculated Licence Notes
Leaked credentials User Offline Free/P1 Valid credentials found in a breach; always high. On-premises passwords are covered only with password hash synchronisation (PHS)
Anonymous IP address Sign-in Real-time Free/P1 Tor or anonymising VPN
Microsoft Entra threat intelligence Sign-in and user Real-time or offline Free/P1 Known attack patterns
Admin confirmed user compromised Sign-in Offline Free/P1 Raised when an admin selects Confirm user compromised
Password spray Sign-in Real-time or offline P2 Fires only when the sprayed password was valid; failed sprays don’t create a detection
Unfamiliar sign-in properties Sign-in Real-time P2 Compares IP, ASN, location, device, browser; new users have a learning period of at least five days
Atypical travel Sign-in Offline P2 Learning period: the earlier of 14 days or 10 sign-ins
Anomalous token Sign-in and user Real-time or offline P2 Possible token replay
Malicious IP address, Suspicious browser, Token issuer anomaly Sign-in Offline P2
Verified threat actor IP Sign-in Real-time P2 Always high
User reported suspicious activity User Offline P2 Needs Report suspicious activity turned on in MFA settings
Attacker in the Middle User Offline Microsoft 365 E5 with EMS E5 Raises the user to high
Impossible travel, New country, Activity from anonymous IP address Sign-in Offline P2 plus Defender for Cloud Apps Signals from Defender for Cloud Apps

Common trap: Assuming leaked-credential detection protects synchronised users regardless of sign-in method - for on-premises passwords it depends on password hash synchronisation, and a cloud password reset remediates the risk for hybrid users only when PHS is enabled.

Get the whole book

This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-300 terms in the glossary · All SC-300 study notes

More SC-300 study notes