Understanding Identity Protection
Azure AD Identity Protection is a feature that works on the principle of risk detection and remediation. It allows administrators to view risk events and detections in the Azure portal and then control what happens when risks are detected. They can also configure notifications regarding alerts about risk activities and receive a weekly report via email. Identity Protection detects and reports on risk classification events based on the following categories:
- Impossible travel
- Anonymous IP addresses
- Unfamiliar sign-in behavior
- Malware-linked IP addresses
- Leaked credentials
- Azure AD threat intelligence
- Password spray
Whenever one of these risk classifications is matched, it results in a remediation action being triggered, such as requiring the affected users to register for/respond to MFA or to perform a password reset. If a risk is deemed significant enough, the affected user can even be blocked entirely until further...