Risky sign-ins
Risky sign-ins are authentication attempts that Microsoft Entra ID Protection flags as suspicious, such as sign-ins from anonymous IPs, atypical travel, or leaked credentials.
Risky sign-ins are authentication events that Microsoft Entra ID Protection evaluates and assigns a risk level — low, medium, or high — based on signals such as anonymous or malicious IP addresses, atypical travel between distant locations, unfamiliar sign-in properties, or leaked credentials. The risk is surfaced in the Entra admin center and can feed Conditional Access policies. The key exam distinction is sign-in risk versus user risk: sign-in risk reflects a single suspicious authentication, while user risk indicates the account itself may be compromised. Conditional Access can require MFA or block access in real time, whereas remediating user risk typically requires a password reset.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →