Microsoft Entra ID
Monitoring

The Risky IP report

In brief

The documentation now notes that the AD FS Risky IP report is being deprecated and links to the Risky IP report workbook. It also updates portal navigation, export handling, notification settings, and threshold guidance.

What Entra admins need to know

Administrators using the report should review the workbook; report exports are now requested through Download Manager and limited to one request per hour.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The Risky IP report

The report provides the following information:

:::image type="content" source="media/how-to-connect-health-adfs/report4a.png" alt-text="Screenshot that shows a Risky IP report with column headings highlighted." lightbox="media/how-to-connect-health-adfs/report4a.png":::

Report item Description
Time Stamp The time stamp that's based on Microsoft Entra admin center local time when the detection time window starts.
All daily events are generated at midnight UTC time.
Hourly events have the time stamp rounded to the beginning of the hour. You can find the first activity start time from “firstAuditTimestamp” in the exported file.
Extranet Lockout Error Count The count of extranet lockout errors that occur from the IP address during the detection time window. The extranet lockout errors can happen multiple times to certain users. This count is displayed only if Extranet Lockout is configured in AD FS (versions 2012R2 and later). Note: We strongly recommend enabling this feature if you allow extranet logins that use passwords.
Unique Users Attempted The count of unique user accounts that are attempted from the IP address during the detection time window. Differentiates between a single user attack pattern and a multi-user attack pattern.

For example,

Open Microsoft Entra Connect Health, select AD FS services, select a service, and then select the following report item indicates that during the 6 PM to 7 PM window on February 28, 2018, theRisky IP address 104.2XX.2XX.9 had no bad password errorsAddresses report. The command bar provides Refresh, Download Manager, Notification Settings, and 284 extranet lockout errors. Fourteen unique users were affected within the criteria. The activity event exceeded the designated report's hourly threshold. Threshold Settings.

:::::image type="content" source="media/how-to-connect-health-adfs/report4b.adfs-risky-ip/connect-health-bad-internet-protocol-addresses.png" alt-text="Screenshot that shows an example of a Riskythe Connect Health bad IP addresses report entry.with callouts for the workbook migration notice, report actions, and results table." lightbox="media/how-to-connect-health-adfs/report4b.adfs-risky-ip/connect-health-bad-internet-protocol-addresses.png":::

:::image type="content" source="media/how-to-connect-health-adfs/report4c.png" alt-text="Screenshot that shows the Risky IP report with the Download, Notification Settings, and Threshold Settings buttons highlighted." lightbox="media/how-to-connect-health-adfs/report4c.png":::

Load balancer IP addresses in the list

Download the Risky IP report

Using the Download functionality, the whole risky IP address list in the past 30 days can be exported from the Connect Health Portal. The export result will include all the failed AD FS sign-in activities in each detection time window, so you can customize the filtering after the export. Besides the highlighted aggregations in the portal, the export result also shows more details about failed sign-in activities per IP address:

Report Item Description

Configure notification settings

You can update the report's administrator contacts through the Notification Settings. By default, the risky IP alert email notification is in an off state. You can enable the notification by toggling the button under Get email notifications for IP addresses exceeding failed activity threshold report.

Like generic alert notification settings in Connect Health, it allows you to customize the designated notification recipient list about the Risky IP report from here. You can also notify all Hybrid Identity Administrators while you're making the change.

Configure threshold settings

You can update the alerting threshold in Threshold Settings. The system threshold is set with default values, which are shown in the following screenshot and described in the table.

The risk IP report threshold settings are separated into four categories.

Screenshot of the Microsoft Entra Connect Health Portal that shows the four categories of threshold settings and their default values.

Threshold setting Description
(Bad U/P + Extranet Lockout) / Day Reports the activity and triggers an alert notification when the count of Bad Password plus the count of Extranet Lockout exceeds the threshold, per day. The default value is 100.

Load balancer IP addresses in the list

Download the Risky IP report

Select Download Manager to review the three most recent export requests or request Download latest report. Export requests are limited to one per hour. A completed request provides a link to the risky IP address list from the past 30 days. The export includes all failed AD FS sign-in activities in each detection time window so that you can customize filtering offline. It also includes the following details:

Report ItemDescription

Configure notification settings

Select Notification Settings to update the report's administrator contacts. By default, the risky IP alert email notification is in an off state. You can enable Get email notifications for IP addresses exceeding failed activity threshold report.

The panel also lets you enable notifications for new service alerts, notify all Global Administrators, and manage custom email recipients.

Configure threshold settings

Select Threshold Settings to update the alerting thresholds. The system default values are described in the following table.

The risk IP report threshold settings are separated into four categories.

Threshold settingDescription
(Bad U/P + Extranet Lockout) / DayReports the activity and triggers an alert notification when the count of Bad Password plus the count of Extranet Lockout exceeds the threshold, per day. The default value is 100.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…