Table of Contents

Identity Protection

Identity Protection is a tool that allows organizations to accomplish three key tasks:

AAD has three Identity Protection policies by default:

The signals generated by and fed to Identity Protection, can be further fed into tools like Conditional Access to make access decisions, or fed back to a security information and event management (SIEM) tool for further investigation based on your organization's enforced policies.
The risk signals can trigger remediation efforts such as requiring users to: perform Azure AD Multi-Factor Authentication, reset their password using self-service password reset, or blocking until an administrator takes action.

User Risk Policy

Sign-in Risk Policy

Azure MFA Registration Policy

Risk Events

AAD detects the following types of risks. The P2 license gives the most detail info, while the P1 license doesn't include all the details.