Understanding Identity Protection
Azure AD Identity Protection is a feature that works on the principle of risk detection and remediation. It allows Microsoft 365 administrators to view risk events and detections in the Azure portal, and then control what happens when risks are detected. They can also configure notifications regarding alerts about risk activities and receive a weekly report via email. Identity Protection will detect and report on risk classification events based on the following categories:
- Impossible travel
- Anonymous IP addresses
- Unfamiliar sign-in behavior
- Malware- linked IP addresses
- Leaked credentials
- Azure AD threat intelligence
Whenever one of these risk classifications is matched, this will result in a remediation action being triggered, such as requiring the affected users to register for/or respond to MFA or being required to perform a password reset. If a risk is deemed significant enough, the affected user can even be blocked...