EBS Analysis: What are risk detections? – Microsoft Entra ID Protection

Understanding Risk Detections in Microsoft Entra ID Protection: A Technical Architecture for Identity Security

Identity has become the primary control plane for modern enterprise security. As organizations accelerate cloud adoption and hybrid work models, the traditional network perimeter has dissolved, leaving identity as the critical boundary between trusted users and potential adversaries. Microsoft Entra ID Protection addresses this reality by providing a sophisticated risk detection engine that continuously evaluates sign-in and user behavior across the identity fabric. For security architects and identity engineers, understanding the taxonomy, mechanics, and operational implications of these detections is essential for building resilient zero trust architectures.

The risk detection framework within Entra ID Protection operates as a multi-layered analytics platform, ingesting signals from authentication events, token characteristics, threat intelligence feeds, and cross-product integrations with Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, and Microsoft Defender for Office 365. Each detection represents a specific attack pattern or anomaly class, categorized by risk level (low, medium, high) and execution mode (real-time or offline). The licensing model—spanning Free, P1, and P2 tiers—determines both the visibility into detection details and the breadth of available detections, creating architectural decisions that directly impact security posture and operational workflows.

Architecture and Detection Taxonomy

Sign-In Risk vs. User Risk

Entra ID Protection separates detections into two fundamental categories: sign-in risk detections and user risk detections. Sign-in risk evaluates the probability that a specific authentication request is malicious, analyzing contextual signals at the moment of authentication. User risk evaluates the probability that an identity has been compromised, aggregating signals over time across multiple sessions and activities. This distinction drives different remediation paths: sign-in risk typically triggers conditional access policies requiring step-up authentication or blocking, while user risk drives identity remediation workflows such as password reset, session revocation, or account disablement.

Real-Time vs. Offline Processing

The detection engine operates in two temporal modes. Real-time detections evaluate signals during the authentication flow, enabling inline enforcement through Conditional Access. These include anonymous IP detection, atypical travel (when sufficient historical data exists), malicious IP address, unfamiliar sign-in properties, and user-reported suspicious MFA activity. Offline detections process aggregated telemetry asynchronously, typically within hours, and include leaked credentials, password spray, Microsoft Entra threat intelligence, and most Defender cross-product integrations. Understanding this distinction is critical for designing response playbooks—real-time detections can prevent compromise, while offline detections require rapid post-breach containment.

Licensing Tiers and Visibility Gaps

The licensing model creates three distinct operational tiers. Microsoft Entra ID Free and P1 licenses provide a baseline set of detections including anonymous IP, leaked credentials, Microsoft Entra threat intelligence, and admin-confirmed user compromise. However, premium detections—atypical travel, malicious IP, password spray, suspicious browser, unfamiliar sign-in properties, anomalous token, token issuer anomaly, admin behavior anomalies, adversary-in-the-middle, PRT theft, suspicious API traffic, and user-reported MFA—require Entra ID P2. Critically, tenants without P2 see premium detections surfaced only as “Additional risk detected” without actionable detail, creating a significant visibility gap that prevents targeted investigation and automated response.

Core Detection Mechanics and Signal Analysis

Anonymity and Infrastructure-Based Detections

Anonymous IP Address detects sign-ins originating from Tor exit nodes, anonymous VPNs, and other infrastructure designed to obscure origin. Available at Free and P1 tiers, this detection operates in real-time by comparing source IPs against continuously updated threat intelligence feeds. The detection flags sessions where actors deliberately hide network identity—a common precursor to credential testing, reconnaissance, or initial access.

Malicious IP Address (P2, real-time) goes beyond anonymity by identifying IPs with demonstrated hostile behavior: high authentication failure rates from invalid credentials, association with known botnets, or correlation with threat intelligence from the Microsoft Threat Intelligence Center (MSTIC). This detection carries higher fidelity than anonymous IP alone because it reflects observed attack activity rather than infrastructure characteristics.

Anonymous Proxy IP (P2 + Defender for Cloud Apps) extends anonymity detection through Defender for Cloud Apps telemetry, identifying proxy infrastructure that may not appear in standard threat feeds. This cross-product detection exemplifies how Entra ID Protection enriches its signal base through the broader Microsoft security ecosystem.

Geospatial and Behavioral Anomaly Detections

Atypical Travel (P2, real-time) remains one of the most operationally valuable detections. The algorithm identifies two sign-ins from geographically distant locations where the time delta is physically impossible for human travel. The engine incorporates multiple mitigating factors: it learns user travel patterns over an initial period (earliest of 14 days or 10 logins), ignores corporate VPN egress points, and accounts for locations regularly used by other organizational users. This contextual awareness reduces false positives from legitimate remote work and business travel.

Atypical Travel (Defender for Cloud Apps) (P2 + Defender for Cloud Apps) applies similar logic to user activity across cloud applications, detecting impossible travel across SharePoint, OneDrive, and other SaaS workloads. This extends geospatial analysis beyond authentication into post-authentication activity.

Unfamiliar Sign-In Properties (P2, real-time) baselines per-user authentication context across IP, ASN, geolocation, device fingerprint, browser profile, and tenant IP subnet. New users enter a dynamic learning mode (minimum five days) during which the detection is suppressed. The detection fires on both interactive and non-interactive sign-ins; non-interactive triggers warrant heightened scrutiny due to token replay attack risk. The investigation interface exposes property-level deviation details, enabling rapid triage.

New Country/Region (P2 + Defender for Cloud Apps) leverages Defender for Cloud Apps’ activity baseline to flag access from previously unseen geographies, complementing the core unfamiliar properties detection with application-layer context.

Credential-Theft and Compromise Detections

Leaked Credentials (Free/P1, offline) represents a uniquely high-fidelity detection. Microsoft operates a continuous credential scanning pipeline monitoring dark web forums, breach dumps, paste sites, law enforcement seizures, and partner feeds. When credentials surface, the service validates them against the tenant’s current password hashes using cryptographic comparison. A detection emits only on confirmed hash match, making this a verified compromise indicator rather than a heuristic. The detection is always classified high risk. Remediation via cloud password reset resolves the risk for cloud identities; for hybrid identities, password hash synchronization (PHS) must be enabled to extend remediation to on-premises directories.

Password Spray (P2, offline) detects successful credential validation during coordinated low-and-slow brute force campaigns across multiple identities. Microsoft monitors spray patterns globally across all Entra tenants. Critically, the detection triggers only on successful password validation—failed spray attempts do not generate detections. When this fires, it confirms an attacker has discovered a valid password for a user in your tenant, though not necessarily that they achieved resource access (MFA may have blocked subsequent steps).

Primary Refresh Token Theft (P2 + Defender for Cloud Apps + Defender for Endpoint) detects compromise of the PRT—a JWT artifact enabling SSO across Windows 10+, Windows Server 2016+, iOS, and Android. Attackers extracting PRTs can bypass MFA and move laterally. This detection fires only in MDE-deployed environments, moves users to high risk immediately, and appears infrequently due to its high severity and low volume.

Adversary-in-the-Middle (AiTM) (Microsoft 365 E5 + EMS E5) represents a high-precision detection for reverse proxy phishing frameworks (e.g., Evilginx2, Modlishka). The Microsoft Security Research team uses Defender for Cloud Apps to identify malicious proxy infrastructure intercepting credentials and session tokens. This detection elevates user risk to high and demands manual investigation—remediation typically requires secure password reset and full session revocation.

Token and Session Anomaly Detections

Anomalous Token (P2, offline) identifies abnormal characteristics in session and refresh tokens: unusual lifetimes, replay from unfamiliar locations, or mismatched application/IP/User-Agent characteristics. The detection historically generated higher noise; recent improvements reduced false positives, though low and medium risk instances still warrant careful validation. This detection is a primary indicator of token theft and replay attacks.

Token Issuer Anomaly (P2, offline) flags SAML tokens where the issuer claims are unusual or match known attacker patterns, indicating potential federation trust abuse or compromised identity providers.

Threat Intelligence and Behavioral Detections

Microsoft Entra Threat Intelligence (Free/P1, offline) surfaces activity consistent with known attack patterns or anomalous for the specific user, drawing from MSTIC and Microsoft security research. This detection appears in logs and ID Protection reports as a consolidated threat intelligence signal.

Suspicious Browser (P2, offline) correlates browser fingerprint anomalies across multiple tenants, identifying sign-in activity from the same browser profile appearing in geographically disparate locations—a signal of credential sharing or browser session hijacking.

Admin Behavior Anomalies (P2, offline) baselines normal administrative operations in Entra ID and flags suspicious directory modifications, triggering against either the acting administrator or the modified object.

Cross-Product Application-Layer Detections

Several detections require Defender for Cloud Apps integration and surface user activity anomalies within SaaS workloads:

  • Mass Access to Sensitive Files (P2 + Defender for Cloud Apps): Triggers when a user accesses an uncommon volume of SharePoint Online or OneDrive files, particularly those containing sensitive information.
  • Suspicious Inbox Forwarding Rules (P2 + Defender for Cloud Apps): Detects creation of rules forwarding all email to external addresses—a classic post-compromise persistence technique.
  • Suspicious Inbox Manipulation Rules (P2 + Defender for Cloud Apps): Identifies rules that delete or move messages/folders, potentially hiding malicious activity or facilitating spam/malware distribution.

Suspicious Email Sending (P2 + Defender for Office 365) flags users restricted from sending email due to suspicious outbound activity, operating at medium risk and low volume.

Suspicious API Traffic / Directory Enumeration (P2, offline) detects abnormal Microsoft Graph API calls suggesting compromised identities conducting reconnaissance—enumerating users, groups, roles, or applications.

Human-In-The-Loop Detections

User Reported Suspicious MFA Activity (P2, real-time) fires when a user denies an MFA prompt and explicitly reports it as suspicious via the “Report suspicious activity” feature (which must be enabled in MFA settings). This detection represents direct human intelligence: the legitimate account owner signaling credential compromise in real time.

Admin Confirmed User Compromised (Free/P1) records when an administrator manually confirms compromise via the risky users UI or API, creating an audit trail with administrator attribution available in risk history.

Implementation Considerations and Architectural Dependencies

Prerequisite Configuration

Effective deployment requires several foundational configurations. Password hash synchronization (PHS) is mandatory for leaked credentials remediation to extend to on-premises identities. The “Report suspicious activity” feature must be enabled in MFA settings for user-reported MFA detections to function. Modern authentication must be enforced—legacy protocol sign-ins generate unfamiliar sign-in properties detections with limited contextual data, increasing false positive rates. Organizations should disable basic authentication via authentication policies or Conditional Access to improve detection fidelity.

Learning Periods and Baseline Establishment

Multiple detections incorporate machine learning baselines with defined warm-up periods. Atypical travel requires the earliest of 14 days or 10 logins to establish a user’s normal travel patterns. Unfamiliar sign-in properties employs a dynamic learning mode (minimum five days) that adapts to the user’s sign-in pattern diversity. Users returning from extended inactivity may re-enter learning mode. Security teams should account for these periods when onboarding new employees or evaluating detection coverage during pilot phases.

Non-Interactive Sign-In Scrutiny

Unfamiliar sign-in properties detected on non-interactive sign-ins (service principals, daemon applications, token refresh flows) deserve increased investigative priority. These flows lack human interaction signals and are primary targets for token replay attacks. Correlating non-interactive anomalies with anomalous token detections can reveal active session hijacking campaigns.

Licensing Architecture Decisions

The P2 licensing requirement for premium detections creates a strategic architectural decision. Organizations on Free or P1 tiers receive only “Additional risk detected” for premium signals—knowing that risk exists without what risk exists. This prevents targeted Conditional Access policies, automated remediation, and meaningful investigation. For enterprises operating zero trust architectures, P2 licensing (or Microsoft 365 E5/EMS E5 bundles) is effectively mandatory to operationalize the full detection taxonomy.

Security and Governance Implications

Risk-Based Conditional Access Integration

The primary operationalization path for sign-in risk detections is Conditional Access policies scoped to risk levels. Real-time detections (anonymous IP, atypical travel, malicious IP, unfamiliar properties, user-reported MFA) can enforce step-up MFA, require compliant devices, or block access inline. Offline detections (leaked credentials, password spray, threat intelligence) require user risk policies that trigger remediation on next sign-in. Architects should design tiered policies: low/medium risk triggers MFA; high risk triggers block or requires password reset via self-service password reset (SSPR).

Automated Remediation Workflows

Entra ID Protection supports automated user risk remediation through “Require password change” policies. For leaked credentials, cloud password reset resolves risk immediately; for hybrid users with PHS, the reset synchronizes on-premises. Session revocation via “Revoke sessions” API or UI action should accompany high-risk user remediation. Organizations should integrate these actions into SOAR playbooks for consistent, auditable response.

False Positive Management

Anomalous token detections at low and medium risk levels carry elevated false positive probability. Security teams should establish triage playbooks that correlate anomalous token with other signals (unfamiliar properties, atypical travel, threat intelligence) before triggering disruptive remediation. High-risk anomalous token detections warrant immediate session revocation and credential rotation. The admin behavior anomaly detection may flag legitimate administrative campaigns (bulk user provisioning, license assignments); maintaining an allow-list of approved administrative service accounts reduces noise.

Audit and Compliance Posture

All risk detections and remediation actions generate audit logs in Entra ID and Microsoft Purview. The admin-confirmed user compromised detection creates an attributable record of human judgment. Organizations subject to regulatory frameworks (NIST 800-53, ISO 27001, SOC 2) should configure log retention and export to SIEM platforms for continuous compliance evidence. The riskEventType values (exposed via Microsoft Graph API) enable programmatic correlation with external threat intelligence platforms.

Operational Implications and SOC Integration

Triage Workflow Design

Effective operationalization requires a tiered triage model. Tier 1 analysts handle high-volume, lower-complexity detections: leaked credentials (automated reset), user-reported MFA (immediate session revocation + password reset), and admin-confirmed compromise (validation of remediation completion). Tier 2 handles correlation-intensive investigations: atypical travel (verifying VPN vs. compromise), unfamiliar sign-in properties (device registration state, location legitimacy), and anomalous token (token lifetime analysis, replay pattern detection). Tier 3 focuses on advanced detections: AiTM (forensic browser session analysis), PRT theft (endpoint forensics via MDE), and suspicious API traffic (Graph permission scope analysis).

Signal Enrichment and Contextualization

Each detection provides enrichment data accessible via the investigation UI and Graph API. Unfamiliar sign-in properties exposes property-level deviation details. Atypical travel shows the two impossible locations and time delta. Leaked credentials indicates the breach source category (dark web, paste site, law enforcement). Security teams should build enrichment playbooks that automatically pull related signals: recent sign-in logs, device compliance state, Intune management status, Defender for Endpoint alerts on the source device, and Defender for Cloud Apps activity for the user.

Volume Management and Alert Fatigue

Organizations with large user populations will experience significant detection volume, particularly from unfamiliar sign-in properties (remote work diversity), Microsoft Entra threat intelligence (broad pattern matching), and anomalous token (residual noise). Implementing risk-level filtering in Conditional Access (e.g., only enforcing MFA on medium/high) and configuring user risk policies to auto-remediate low-risk leaked credentials via SSPR reduces analyst burden. Custom detection rules in Microsoft Sentinel or SIEM can further correlate and deduplicate before alert generation.

Hybrid Identity Considerations

For hybrid environments, leaked credentials detection and remediation require PHS. Without PHS, on-premises password compromise detected via cloud hash matching cannot be remediated through cloud password reset—the on-premises credential remains valid. Organizations using Pass-Through Authentication (PTA) or federation without PHS must implement parallel on-premises remediation workflows (AD password reset, account unlock). Additionally, atypical travel and unfamiliar properties may generate false positives for users authenticating through on-premises AD FS or PTA agents with differing egress IPs; configuring trusted IP ranges and corporate VPN exclusions mitigates this.

Common Pitfalls and Anti-Patterns

Treating “Additional Risk Detected” as Actionable Intelligence

Organizations on Free or P1 licenses often attempt to operationalize “Additional risk detected” alerts. Without detection detail, this signal cannot drive targeted Conditional Access, specific remediation, or meaningful investigation. The only operational responses are generic: block all medium/high risk sign-ins (high false positive impact) or ignore (security gap). This is a licensing architecture decision, not a configuration gap.

Disabling Detections Instead of Tuning

Some teams disable noisy detections (particularly unfamiliar sign-in properties and anomalous token) rather than investing in baseline tuning and correlation logic. This creates blind spots for token replay and credential stuffing attacks. The correct approach is retaining detections, enriching with device/location context, and building correlation rules that distinguish legitimate pattern changes (new device enrollment, travel) from attack patterns.

Ignoring Non-Interactive Sign-In Anomalies

Focusing exclusively on interactive sign-in risk misses the majority of token replay and service principal compromise scenarios. Non-interactive unfamiliar properties and anomalous token detections are early indicators of machine identity compromise. Security programs must extend monitoring and response playbooks to service principals, managed identities, and daemon applications.

Incomplete Cross-Product Licensing

Deploying Entra ID P2 without Defender for Cloud Apps, Defender for Endpoint, or Defender for Office 365 leaves significant detection gaps: anonymous proxy IP, mass file access, inbox rule anomalies, new country detection, PRT theft, suspicious email sending, and AiTM all require cross-product licenses. License planning should map required detections to the minimal licensing bundle covering the desired detection taxonomy.

Insufficient Learning Period Accommodation

New hire onboarding and M&A integration often coincide with elevated detection volume as users exit learning modes. Security operations should coordinate with HR/IT onboarding workflows to pre-register devices, configure compliant authentication methods, and temporarily adjust risk policy thresholds during transition periods.

Why This Matters to Enterprise IT

The risk detection framework in Microsoft Entra ID Protection is not a feature checklist—it is the sensory nervous system of a zero trust identity architecture. Each detection class maps to a specific adversary tactic in the MITRE ATT&CK framework: credential access (leaked credentials, password spray), initial access (AiTM, anonymous IP), persistence (inbox rules, PRT theft), defense evasion (anomalous token, token issuer anomaly), discovery (suspicious API traffic), and lateral movement (atypical travel, unfamiliar properties).

For enterprise IT, the stakes are concrete. A missed leaked credentials detection enables credential stuffing campaigns that bypass perimeter controls. An uninvestigated atypical travel signal may be the first indicator of a compromised executive account used for business email compromise. An ignored anomalous token detection at medium risk may represent an active session hijack allowing persistent access despite MFA. The licensing tier determines whether your security team sees the attack trajectory or only a generic “additional risk” placeholder.

Operationally, these detections feed the three pillars of identity security: prevention (real-time Conditional Access), detection (offline risk aggregation), and response (automated remediation, SOAR integration). Organizations that treat Entra ID Protection as a reporting dashboard rather than an enforcement engine forfeit the preventive value of real-time detections and the containment speed of automated user risk remediation.

EBS Consulting Perspective

From an enterprise consulting standpoint, we observe three recurring patterns in Entra ID Protection deployments that determine security outcomes.

First, licensing alignment with threat model. Organizations adopting zero trust but remaining on P1 licenses effectively operate with degraded sensors. The “Additional risk detected” blind spot means premium attack patterns—AiTM, PRT theft, password spray, token replay—generate alerts without investigation context. We advise clients to model the cost of P2 (or E5/EMS E5) against the risk of undetected identity compromise, factoring in regulatory exposure, intellectual property value, and incident response costs. For most mid-market and enterprise clients, the incremental licensing cost is negligible compared to a single identity breach.

Second, detection-to-enforcement gap closure. Many tenants enable Entra ID Protection but fail to configure Conditional Access policies that actually consume risk signals. Real-time detections without enforcement policies are audit logs, not security controls. We implement a standard policy framework: Block high-risk sign-ins; Require MFA + compliant device for medium-risk; Allow low-risk with monitoring. For user risk: Require password change on high/medium; Allow low with monitoring. This baseline closes the enforcement gap while maintaining usability.

Third, cross-product telemetry integration. The highest-fidelity detections—AiTM, PRT theft, mass file access, inbox anomalies—require Defender for Cloud Apps, Defender for Endpoint, and Defender for Office 365. Organizations that procure Entra ID P2 but not the Defender suite leave the most sophisticated attack vectors undetected. We architect licensing and deployment roadmaps that align identity protection investments with endpoint, cloud app, and email security capabilities to unlock the full detection taxonomy.

Beyond deployment, we emphasize operational maturity. Detection volume without triage process creates alert fatigue. We help clients build runbooks mapped to each detection class, integrate with SIEM/SOAR platforms (Microsoft Sentinel, Splunk, Chronicle), and establish metrics: mean time to triage, mean time to remediate, false positive rate by detection type, and coverage of MITRE ATT&CK techniques. The goal is not maximum alerts—it is minimum dwell time for identity compromise.

Practical Next Steps

  1. Inventory current licensing and detection coverage. Map your Entra ID tier (Free/P1/P2) and Defender suite licenses against the detection taxonomy. Identify which premium detections are invisible (“Additional risk detected”) and which cross-product detections are unavailable.
  2. Enable foundational prerequisites. Verify PHS is configured for hybrid identities. Enable “Report suspicious activity” in MFA settings. Enforce modern authentication and block legacy protocols via Conditional Access or authentication policies.
  3. Deploy baseline Conditional Access risk policies. Implement sign-in risk policy (block high, MFA medium) and user risk policy (password reset high/medium). Test in report-only mode before enforcement.
  4. Configure automated remediation. Enable “Require password change” for user risk. Validate SSPR registration coverage across the user population. Test end-to-end leaked credentials remediation for cloud and hybrid users.
  5. Build detection-specific triage runbooks. Start with the top five detections by volume in your tenant. Document enrichment steps, correlation logic, decision trees, and escalation paths. Include non-interactive sign-in investigation procedures.
  6. Integrate with SIEM/SOAR. Export Entra ID Protection risk events via Graph API or diagnostic settings. Build correlation rules that combine risk signals with Defender alerts, network logs, and HR/IT context (travel, onboarding, role changes).
  7. Establish measurement and continuous improvement. Track detection coverage against MITRE ATT&CK, false positive rates by detection type, mean time to remediate, and policy enforcement effectiveness. Review quarterly and adjust baselines, policies, and runbooks.

Conclusion

Microsoft Entra ID Protection’s risk detection engine provides a comprehensive, multi-signal view of identity compromise that few platforms can match—spanning real-time authentication analysis, offline threat intelligence correlation, cross-product behavioral analytics, and human-in-the-loop reporting. But the architecture only delivers value when licensing, configuration, enforcement, and operations align. The detections are not the solution; they are the input to a solution that your security program must build.

Escape Business Solutions partners with enterprises to transform these detections from raw signals into operationalized identity defense. Whether you are evaluating licensing strategy, designing Conditional Access enforcement, building SOC runbooks, or integrating with a broader zero trust architecture, our identity security practice brings implementation experience across regulated industries, complex hybrid environments, and large-scale M&A integrations. The risk detections are already firing in your tenant. The question is whether your organization sees them, understands them, and acts on them before an adversary turns a signal into a breach.

Let’s discuss how to close the gap between detection and defense.

EBS Consulting Advice

If your organization is evaluating What are risk detections? – Microsoft Entra ID Protection, do not treat the technology decision in isolation. Start with the business outcome, current architecture, security and identity controls, operational constraints, migration dependencies and governance requirements. A practical assessment should identify the current-state gaps, prioritize the risks and define an implementation roadmap with measurable outcomes.

EBS can help assess the environment, develop the architecture and modernization roadmap, and translate the technical options into an actionable business plan. Relevant EBS services: Escape Cloud Microsoft Solution Assessments Modern Workplace.

Have a technology challenge? Email info@escapebusinesssolutions.com to describe your situation. We welcome questions, consulting discussions and requests for a proposal.


Discover more from Escape Business Solutions

Subscribe to get the latest posts sent to your email.