## Configure risk policies
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor both types ofΒ [risk policies](../id-protection/concept-identity-protection-policies.md)Β in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
1. Set up the following key foundational policies.
- [User risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md): Trigger actions (such as require a secure password change for high-risk users).
- [Sign-in risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md#sign-in-risk-policy-in-conditional-access): Evaluate each sign-in attempt and enforce controls such as multifactor authentication (MFA) or block access.
- [MFA registration policy](../id-protection/howto-identity-protection-configure-mfa-policy.md): Ensure user enrollment in MFA before they become risky.
1. Make decisions based on the [investigation and risk remediation framework](../id-protection/howto-identity-protection-investigate-risk.md#investigation-and-risk-remediation-framework).
1. Use [Microsoft Graph PowerShell](../id-protection/howto-identity-protection-graph-api.md) or APIs for bulk actions.
For deeper analysis, [export risk data](../id-protection/howto-export-risk-data.md) to security information and event management (SIEM) tools (such as Microsoft Sentinel) or [Log Analytics](../id-protection/howto-export-risk-data.md#log-analytics).
## Monitor and tune policies
1. Use the [Impact analysis of risk-based access policies workbook](../id-protection/workbook-risk-based-policy-impact.md) for trend analysis.
1. To simulate policy effects, enable [report-only mode in Conditional Access](../identity/conditional-access/concept-conditional-access-report-only.md).
## Configure risk policies
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and UserΒ [risk policies](../id-protection/concept-identity-protection-policies.md)Β in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
1. Set up the following key foundational policies.
- [User risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md): Trigger actions such as require a secure password change for high-risk users.
- [Sign-in risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md#sign-in-risk-policy-in-conditional-access): Evaluate each sign-in attempt and enforce controls such as multifactor authentication (MFA) or block access.
- [MFA registration policy](../id-protection/howto-identity-protection-configure-mfa-policy.md): Ensure user enrollment in MFA before they become risky.
1. Make decisions based on the [investigation and risk remediation framework](../id-protection/howto-identity-protection-investigate-risk.md#investigation-and-risk-remediation-framework).
1. Use [Microsoft Graph PowerShell](../id-protection/howto-identity-protection-graph-api.md) or APIs for bulk actions.
For deeper analysis, [export risk data](../id-protection/howto-export-risk-data.md) to security information and event management (SIEM) tools such as Microsoft Sentinel or [Log Analytics](../id-protection/howto-export-risk-data.md#log-analytics).
## Monitor and tune policies
1. Use the [Impact analysis of risk-based access policies workbook](../id-protection/workbook-risk-based-policy-impact.md) for trend analysis.
1. To simulate policy effects, enable [report-only mode in Conditional Access](../identity/conditional-access/concept-conditional-access-report-only.md).