How to Set Up Entra ID Identity Protection
Microsoft Entra ID Identity Protection uses machine learning to detect sign-in risks and user risks in real time. When a risky sign-in is detected, Identity Protection can automatically require MFA, force a password reset, or block access - without admin intervention.
How Identity Protection works
Entra ID analyses every sign-in against signals from Microsoft threat intelligence - leaked credentials, anonymous IPs, unfamiliar properties, impossible travel. It assigns a risk level (Low, Medium, High) and your policies decide what to do.
- Sign-in risk - the specific sign-in looks suspicious
- User risk - the account is considered compromised (e.g. credentials found in a data breach)
Requires Entra ID P2 (Microsoft 365 E5 or Entra ID P2 add-on).
Configure sign-in risk policy
Configure user risk policy
Risk detections
Investigating and remediating
If genuine compromise: Block sign-in, Reset password, Revoke sessions, Review what account accessed during compromise period, Confirm compromised in Identity Protection.
Frequently Asked Questions
Partially. Identity Protection can detect risks without CA. But automated remediation requires Conditional Access risk-based policies.
If you have a user risk policy configured, High risk users are blocked until they complete a password reset via SSPR.
Yes. Sign in with a test account via the Tor Browser - this generates an Anonymous IP detection within minutes.