A cloud-based identity and access management service for securing user authentication and resource access
The most important point is: the Weekly Digest and the Risky sign-ins report are not always a one-to-one view of the same data. The digest can count new risky sign-ins/detections when they occur, while the portal view depends on the report you open, the risk state filter, processing time, permissions, license level, and retention.
I would validate it in this order:
- In ID Protection > Risky sign-ins, set the time range to cover the digest period and explicitly include Remediated in the Risk state filter. Microsoft documents that notification emails can include detections when they occur, even if the risk is later resolved automatically, and that remediated sign-ins may not appear unless that state is included.
- Check ID Protection > Risk detections, not only Risky sign-ins. Some Identity Protection detections are user-risk detections or otherwise better investigated from the Risk detections report rather than the Risky sign-ins report.
- Wait for processing if the digest is very recent. Microsoft documents that real-time detection details can take several minutes to appear in reports, while offline detections can take longer.
- Confirm the account you are using has enough permission to view the reports. Microsoft’s investigation guidance lists Reports Reader as the least privileged role for viewing sign-in and audit logs.
- Check retention and licensing. Microsoft documents different retention windows for risky sign-ins depending on license tier, for example 7 days for Entra ID Free, 30 days for P1, and 90 days for P2.
If all of those checks still show no data, collect the digest email timestamp, the count shown in the digest, screenshots of the Risky sign-ins and Risk detections filters, your license tier, and the admin role used for the query. At that point I would open a Microsoft support case, because the digest and portal reports should at least be explainable by risk state, report type, latency, permission, license, or retention.
One practical note: I would not dismiss the alert just because the default Risky sign-ins view is empty. Treat the digest as a trigger to check both Risk detections and remediated risky sign-ins, then document why no active risk remains.
Relevant documentation:
- Configure Microsoft Entra ID Protection notifications: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-notifications
- Investigate risk with Microsoft Entra ID Protection: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk
- Risk detection types and levels: https://learn.microsoft.com/en-us/entra/id-protection/concept-risk-detection-types
- What are risk detections?: https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks
- Microsoft Entra data retention: https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention
Disclosure: Drafted with help from ChatGPT and reviewed against the Microsoft documentation linked above.
and click on Yes for was this answer helpful. And, if you have any further query do let us know.