The signed in user is not assigned to a role for the signed in application. Assign the user to the application.

Yao Lu 40 Reputation points
2023-08-03T14:02:58.6433333+00:00

I'm clear with the meaning of above decription. Just wonder in this case, if the the user's password authentication succeeded or not, so I can judge, as a security professional, if the user's account was compromised and take actions correspondingly.

The same case for Sign-in was blocked due to real-time detection rule(s): ***

I only know the access was blocked, not know if the pass auth was successful already.

Thank you.

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,658 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,235 questions
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 37,186 Reputation points Microsoft Employee
    2023-08-04T23:07:24.84+00:00

    Hi @Yao Lu ,

    Thanks for your post! Identity protection only comes into play when primary Credentials are successful. Smart lockout is the closest solution to prevent first-factor/primary credentials and detect risk at that level. Using smart lockout, if primary credentials are successful, we detect a risk, and there is a policy to change the password, we will request that to happen or block the user.

    https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks

    Let me know if this helps and if you have further questions.

    If the information addressed your question, please Accept the answer. This will help us as well as others in the community who may be researching similar information.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.