CA policy is getting applied on the user for risky user in AAD but the user is not showing in the risky users report

Ajaz Khan 266 Reputation points
2022-09-20T17:45:36.02+00:00

Hello there,
We have a CA policy created to enforce MFA for the risky users in AAD. The policy is getting applied on one of the user accounts and prompts for the MFA however when we check we don't find that user in the risky user report in AAD.
We have already checked what if for the CA policy and the sign in logs. The sign in logs show that MFA was prompted because the user was flagged risky. We want to know how the CA policy is getting applied when the user is not found in risky users list.
Any help would be appreciated.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,562 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.2K Reputation points MVP
    2022-09-20T17:55:49.79+00:00

    Is this a guest user? They dont show up in the Risky User List.
    Is there also a Risky Sign in policy?


  2. Andy David - MVP 142.2K Reputation points MVP
    2022-09-21T14:31:26.583+00:00

    Ok, thats what I meant, you are using a CA policy or Identity Protection
    Are you licensed with a P2? Do you see other accounts listed?

    https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection#license-requirements

    243522-image.png

    0 comments No comments