The difference between the two risk types, real-time versus offline detections, and which detections need P2.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
Every detection contributes either to sign-in risk (the probability that a given authentication request isn’t from the account owner) or to user risk (the probability that the identity itself is compromised). Risk is graded low, medium or high, and some detections are calculated in real time while others are calculated offline.
| Aspect | Real-time | Offline |
|---|---|---|
| When calculated | During the sign-in | After the sign-in |
| Time to appear in reports | 5-10 minutes | Up to 48 hours |
| Sign-in risk effect | Can be remediated during the sign-in by a Conditional Access policy (for example, require MFA) | Can’t be remediated in that sign-in; unremediated sign-in risk can aggregate into user risk |
| User risk effect | Remediated through a Conditional Access policy, such as a secure password change | User is blocked at next sign-in until they remediate, if a policy applies |
Low-risk detections and users age out after six months; medium and high risk persist until remediated or dismissed. Leaked credentials and Verified threat actor IP are always high risk. Sign-ins from trusted named locations lower the calculated sign-in risk, which is why corporate egress ranges should be defined as trusted locations.
| Detection | Risk type | Calculated | Licence | Notes |
|---|---|---|---|---|
| Leaked credentials | User | Offline | Free/P1 | Valid credentials found in a breach; always high. On-premises passwords are covered only with password hash synchronisation (PHS) |
| Anonymous IP address | Sign-in | Real-time | Free/P1 | Tor or anonymising VPN |
| Microsoft Entra threat intelligence | Sign-in and user | Real-time or offline | Free/P1 | Known attack patterns |
| Admin confirmed user compromised | Sign-in | Offline | Free/P1 | Raised when an admin selects Confirm user compromised |
| Password spray | Sign-in | Real-time or offline | P2 | Fires only when the sprayed password was valid; failed sprays don’t create a detection |
| Unfamiliar sign-in properties | Sign-in | Real-time | P2 | Compares IP, ASN, location, device, browser; new users have a learning period of at least five days |
| Atypical travel | Sign-in | Offline | P2 | Learning period: the earlier of 14 days or 10 sign-ins |
| Anomalous token | Sign-in and user | Real-time or offline | P2 | Possible token replay |
| Malicious IP address, Suspicious browser, Token issuer anomaly | Sign-in | Offline | P2 | |
| Verified threat actor IP | Sign-in | Real-time | P2 | Always high |
| User reported suspicious activity | User | Offline | P2 | Needs Report suspicious activity turned on in MFA settings |
| Attacker in the Middle | User | Offline | Microsoft 365 E5 with EMS E5 | Raises the user to high |
| Impossible travel, New country, Activity from anonymous IP address | Sign-in | Offline | P2 plus Defender for Cloud Apps | Signals from Defender for Cloud Apps |
Common trap: Assuming leaked-credential detection protects synchronised users regardless of sign-in method - for on-premises passwords it depends on password hash synchronisation, and a cloud password reset remediates the risk for hybrid users only when PHS is enabled.
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.