πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since August 21st 2025, 8:08 PM PDT

Report generated on August 22nd 2025, 8:08 PM PDT

πŸ“Š Summary

9
Total Commits
0
New Files
6
Modified Files
0
Deleted Files
6
Contributors

πŸ“ Modified Documentation Files

Modified by Lynne O'Connor on Aug 22, 2025 3:52 PM
πŸ“– View on learn.microsoft.com
+17 / -17 lines changed
Commit: resolve Gargi comments.3
Changes:
Before
After
ms.author: gasinh
ms.service: entra-id-protection
ms.topic: concept-article
ms.date: 08/21/2025
 
#CustomerIntent: As an IT admin, I want to learn, deploy, and test Microsoft Entra ID Protection so that I can detect, investigate, and remediate identity-based risks.
---
 
## Understand the products
 
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with the resources in this section:
 
- [What is Microsoft Entra ID Protection?](../id-protection/overview-identity-protection.md) explains how you can feed identity-based risks into tools like Conditional Access (CA) to make access decisions. You can also send them to a security information and event management (SIEM) tool for investigation and correlation.
 
- Tables in the [What are risk detections](../id-protection/concept-identity-protection-risks.md) article summarize sign-in and user risk detections, their license requirements, and whether the detection occurs in real-time or offline.
- [How to investigate risks](../id-protection/howto-identity-protection-investigate-risk.md) describes how to use Microsoft Entra ID Protection reports to investigate identity risks in your environment.
- [Risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) explains how to use the sign-in risk policy and user risk policy to allow users to self-remediate detected risks.
- [Microsoft Graph PowerShell SDK and Microsoft Entra ID Protection](../id-protection/howto-identity-protection-graph-api.md) shows you how to use Microsoft Graph data to manage risky users.
- [How to export risk data](../id-protection/howto-export-risk-data.md) describes methods to export risk data from Microsoft Entra ID Protection for long-term storage and analysis.
 
ms.author: gasinh
ms.service: entra-id-protection
ms.topic: concept-article
ms.date: 08/22/2025
 
#CustomerIntent: As an IT admin, I want to learn, deploy, and test Microsoft Entra ID Protection so that I can detect, investigate, and remediate identity-based risks.
---
 
## Understand the products
 
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:
 
- Learn how [Microsoft Entra ID Protection](../id-protection/overview-identity-protection.md) helps you feed identity-based risks into tools like Conditional Access (CA) to make access decisions. You can send risks to a security information and event management (SIEM) tool for investigation and correlation.
 
- Learn about [sign-in and user risk detections](../id-protection/concept-identity-protection-risks.md) license requirements and whether detections occur in real-time or offline.
- Learn how Microsoft Entra ID Protection reports help you to [investigate risks](../id-protection/howto-identity-protection-investigate-risk.md) in your environment.
- Learn how to allow users to self-remediate detected risks with [sign-in risk and user risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md).
- Learn how to manage risky users with [Microsoft Graph data](../id-protection/howto-identity-protection-graph-api.md).
- Learn how to [export risk data](../id-protection/howto-export-risk-data.md) from Microsoft Entra ID Protection for long-term storage and analysis.
 
Modified by Lynne O'Connor on Aug 22, 2025 4:23 PM
πŸ“– View on learn.microsoft.com
+5 / -5 lines changed
Commit: resolved Gargi comments.5
Changes:
Before
After
- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
- [Bring identity risk-related telemetry into security investigations](id-protection-guide-investigate.md)
 
This article helps administrators to identify and remediate identity risks for users accessing enterprise-managed resources, including Microsoft 361. Use real-time and offline risk detections to evaluate sign-ins and user behavior. Apply automated responses such as multifactor authentication (MFA), password resets, or block access based on risk levels. Risk-based conditional access policies that scale across large environments enforce these protections.
 
Configure the following features for user self-remediation of identity risk for enterprise-managed resources with Microsoft Entra ID Protection:
 
 
Configure Conditional Access policies for users with dynamic enforcement based on:
 
1. [Sign-in risk](../id-protection/concept-identity-protection-risks.md) (such as from an unfamiliar location or device)
1. [User risk](../id-protection/concept-identity-protection-risks.md#user-risk-detections) (such as leaked credentials or suspicious behavior)
 
Require users to verify their identity or restrict access to sensitive apps until after risk mitigation.
 
 
Configure user alerts and notifications for the following scenarios:
 
1. Suspicious activity on their account
1. Required actions to maintain access (such as reauthentication or device compliance)
- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
- [Bring identity risk-related telemetry into security investigations](id-protection-guide-investigate.md)
 
This article helps administrators to identify and remediate identity risks for users accessing enterprise-managed resources, including Microsoft 365. Use real-time and offline risk detections to evaluate sign-ins and user behavior. Apply automated responses such as multifactor authentication (MFA), password resets, or block access based on risk levels. Risk-based conditional access policies that scale across large environments enforce these protections.
 
Configure the following features for user self-remediation of identity risk for enterprise-managed resources with Microsoft Entra ID Protection:
 
 
Configure Conditional Access policies for users with dynamic enforcement based on:
 
1. [Sign-in risk](../id-protection/concept-identity-protection-risks.md) such as from an unfamiliar location or device.
1. [User risk](../id-protection/concept-identity-protection-risks.md#user-risk-detections) such as leaked credentials or suspicious behavior.
 
Require users to verify their identity or restrict access to sensitive apps until after risk mitigation.
 
 
Configure user alerts and notifications for the following scenarios:
 
1. Suspicious activity on their account.
1. Required actions to maintain access such as reauthentication or device compliance.
Modified by Lynne O'Connor on Aug 22, 2025 4:23 PM
πŸ“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: resolved Gargi comments.5
Changes:
Before
After
 
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
 
1. [Risky sign-ins](../id-protection/howto-identity-protection-investigate-risk.md#risky-sign-ins-report) (such as [impossible travel](../id-protection/howto-identity-protection-investigate-risk.md#investigating-atypical-travel-detections), [anonymous IPs, and malware-linked IPs](../id-protection/howto-identity-protection-investigate-risk.md#investigating-malicious-ip-address-detections))
1. [Risky users](../id-protection/howto-identity-protection-investigate-risk.md#risky-users-report) (such as accounts with [leaked credentials](../id-protection/howto-identity-protection-investigate-risk.md#investigating-leaked-credentials-detections) and [suspicious behavior](../id-protection/howto-identity-protection-investigate-risk.md#investigating-password-spray-detections))
1. [Risk detections](../id-protection/howto-identity-protection-investigate-risk.md#risk-detections-report) (such as [token replay](../id-protection/howto-identity-protection-investigate-risk.md#investigating-anomalous-token-and-token-issuer-anomaly-detections) and unfamiliar sign-in properties)
 
## Investigate with Microsoft Security Copilot in Microsoft Entra
 
 
1. Review logs in the Microsoft Entra admin center.
1. For correlation and storage, export logs to [Azure Monitor Log Analytics](../identity/monitoring-health/howto-analyze-activity-logs-log-analytics.md), [Microsoft Sentinel](/azure/sentinel/overview?tabs=defender-portal), or your dedicated SIEM.
1. Generate alerts for specific actions (such as policy changes, user unblocks).
 
## Configure access in multitenant environments
 
 
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
 
1. [Risky sign-ins](../id-protection/howto-identity-protection-investigate-risk.md#risky-sign-ins-report) such as [impossible travel](../id-protection/howto-identity-protection-investigate-risk.md#investigating-atypical-travel-detections), [anonymous IPs, and malware-linked IPs](../id-protection/howto-identity-protection-investigate-risk.md#investigating-malicious-ip-address-detections).
1. [Risky users](../id-protection/howto-identity-protection-investigate-risk.md#risky-users-report) such as accounts with [leaked credentials](../id-protection/howto-identity-protection-investigate-risk.md#investigating-leaked-credentials-detections) and [suspicious behavior](../id-protection/howto-identity-protection-investigate-risk.md#investigating-password-spray-detections).
1. [Risk detections](../id-protection/howto-identity-protection-investigate-risk.md#risk-detections-report) such as [token replay](../id-protection/howto-identity-protection-investigate-risk.md#investigating-anomalous-token-and-token-issuer-anomaly-detections) and unfamiliar sign-in properties.
 
## Investigate with Microsoft Security Copilot in Microsoft Entra
 
 
1. Review logs in the Microsoft Entra admin center.
1. For correlation and storage, export logs to [Azure Monitor Log Analytics](../identity/monitoring-health/howto-analyze-activity-logs-log-analytics.md), [Microsoft Sentinel](/azure/sentinel/overview?tabs=defender-portal), or your dedicated SIEM.
1. Generate alerts for specific actions such as policy changes, user unblocks.
 
## Configure access in multitenant environments
 
Modified by Lynne O'Connor on Aug 22, 2025 4:23 PM
πŸ“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: resolved Gargi comments.5
Changes:
Before
After
 
## Configure risk policies
 
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor both types ofΒ [risk policies](../id-protection/concept-identity-protection-policies.md)Β in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
 
1. Set up the following key foundational policies.
 
- [User risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md): Trigger actions (such as require a secure password change for high-risk users).
- [Sign-in risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md#sign-in-risk-policy-in-conditional-access): Evaluate each sign-in attempt and enforce controls such as multifactor authentication (MFA) or block access.
- [MFA registration policy](../id-protection/howto-identity-protection-configure-mfa-policy.md): Ensure user enrollment in MFA before they become risky.
1. Make decisions based on the [investigation and risk remediation framework](../id-protection/howto-identity-protection-investigate-risk.md#investigation-and-risk-remediation-framework).
1. Use [Microsoft Graph PowerShell](../id-protection/howto-identity-protection-graph-api.md) or APIs for bulk actions.
 
For deeper analysis, [export risk data](../id-protection/howto-export-risk-data.md) to security information and event management (SIEM) tools (such as Microsoft Sentinel) or [Log Analytics](../id-protection/howto-export-risk-data.md#log-analytics).
 
## Monitor and tune policies
 
1. Use the [Impact analysis of risk-based access policies workbook](../id-protection/workbook-risk-based-policy-impact.md) for trend analysis.
1. To simulate policy effects, enable [report-only mode in Conditional Access](../identity/conditional-access/concept-conditional-access-report-only.md).
 
## Configure risk policies
 
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and UserΒ [risk policies](../id-protection/concept-identity-protection-policies.md)Β in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
 
1. Set up the following key foundational policies.
 
- [User risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md): Trigger actions such as require a secure password change for high-risk users.
- [Sign-in risk policy](../id-protection/howto-identity-protection-configure-risk-policies.md#sign-in-risk-policy-in-conditional-access): Evaluate each sign-in attempt and enforce controls such as multifactor authentication (MFA) or block access.
- [MFA registration policy](../id-protection/howto-identity-protection-configure-mfa-policy.md): Ensure user enrollment in MFA before they become risky.
1. Make decisions based on the [investigation and risk remediation framework](../id-protection/howto-identity-protection-investigate-risk.md#investigation-and-risk-remediation-framework).
1. Use [Microsoft Graph PowerShell](../id-protection/howto-identity-protection-graph-api.md) or APIs for bulk actions.
 
For deeper analysis, [export risk data](../id-protection/howto-export-risk-data.md) to security information and event management (SIEM) tools such as Microsoft Sentinel or [Log Analytics](../id-protection/howto-export-risk-data.md#log-analytics).
 
## Monitor and tune policies
 
1. Use the [Impact analysis of risk-based access policies workbook](../id-protection/workbook-risk-based-policy-impact.md) for trend analysis.
1. To simulate policy effects, enable [report-only mode in Conditional Access](../identity/conditional-access/concept-conditional-access-report-only.md).
+3 / -2 lines changed
Commit: sla-note
Changes:
Before
After
ms.service: entra-id
ms.topic: overview
ms.subservice: monitoring-health
ms.date: 08/18/2025
ms.author: sarahlipsey
ms.reviewer: jadedsouza
ms.custom: sfi-ga-nochange
 
![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)
 
Each recommendation contains a description, a summary of the value of addressing the recommendation, and a step-by-step action plan. If applicable, impacted resources associated with the recommendation are listed, so you can resolve each affected area. If a recommendation doesn't have any associated resources, the impacted resource type is *Tenant level*, so your step-by-step action plan impacts the entire tenant and not just a specific resource.
 
## Recommendations overview table
 
 
ms.service: entra-id
ms.topic: overview
ms.subservice: monitoring-health
ms.date: 08/22/2025
ms.author: sarahlipsey
ms.reviewer: jadedsouza
ms.custom: sfi-ga-nochange
 
![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)
 
Each recommendation contains a description, a summary of the value of addressing the recommendation, and a step-by-step action plan. If applicable, impacted resources associated with the recommendation are listed, so you can resolve each affected area. If a recommendation doesn't have any associated resources, the impacted resource type is *Tenant level*, so your step-by-step action plan impacts the entire tenant and not just a specific resource. The system processes recommendation data daily, reflecting activity from the preceding 24-hour window. Occasionally, data synchronization may extend up to 72 hours.
 
 
## Recommendations overview table
 
+2 / -2 lines changed
Commit: sla-note
Changes:
Before
After
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 06/12/2025
ms.author: sarahlipsey
ms.reviewer: jadedsouza
ms.custom: sfi-image-nochange
 
![Screenshot of the list of recommendations.](media/howto-use-recommendations/recommendations-list.png)
 
Each recommendation provides the same set of details that explain what the recommendation is, why it's important, and how to fix it. The recommendation service runs every 24-48 hours, depending on the recommendation.
 
![Screenshot of a recommendation's status, priority, and impacted resource type.](media/howto-use-recommendations/recommendation-status-risk.png)
 
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 08/22/2025
ms.author: sarahlipsey
ms.reviewer: jadedsouza
ms.custom: sfi-image-nochange
 
![Screenshot of the list of recommendations.](media/howto-use-recommendations/recommendations-list.png)
 
Each recommendation provides the same set of details that explain what the recommendation is, why it's important, and how to fix it. Recommendation data refreshes every 24 hours with a one-day lag. In rare instances, updates may take up to 72 hours to appear.
 
![Screenshot of a recommendation's status, priority, and impacted resource type.](media/howto-use-recommendations/recommendation-status-risk.png)