Hello anonymous user-2701,
Thanks for reaching out.
Ideally, this occurs when your organization has configured the Sign-in risk policy/User risk policy from Identity Protection policies as described here so that users' access is blocked when a risk is detected.
If self-remediation options have previously been setup, users can unblock access by using Azure AD Multi-Factor Authentication (MFA) and self-service password reset (SSPR). Otherwise, company administrators must manually check users' risky events and mitigate them. For further information, see how risk remediation works.
Hope this helps.
-----
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.