Protecting users with risk and registration policies
With Identity Protection, you can protect users with risk policies. These can be separated into the following categories:
- User risk policies
- Sign-in risk policies
It is also possible to protect your users with an MFA registration policy.
Let’s examine each of these policies and take a look at how you can start to configure them.
Configuring user risk and sign-in risk policies
User risk policies and sign-in risk policies are similar in what they do. They are both capable of allowing or blocking access to Azure AD based on risk. With a user risk policy, you can block or allow access and require a password change, whereas with a sign-in risk policy, you can block or allow access and require MFA.
This difference between the two can be seen in the following screenshot in terms of the control enforcements of Require password change and Block access that can be applied: