Planning for Identity Protection
Azure Identity Protection is an Azure AD Premium P2 feature (with a few limited features available in P1) that allows organizations to identify several types of risks in the Azure AD environment based on signals received and processed, including the following:
- Impossible or atypical travel (logging in from two geographically distant areas in a very short amount of time)
- Usage of anonymous IP addresses or address ranges
- Usage of malware-linked IP addresses
- Leaked credentials, such as end user or workload identity client ID or secret values
- Password spray attempts
These risks are categorized into three tiers: low, medium, and high. While Microsoft doesn’t provide exact details on what signals or combinations of signals are used as the basis of categorization, it does provide reporting and workflows that can mitigate the risks.
Note
Identity Protection features are based on machine learning and need to gather...