Hi @Yao Lu ,
Thanks for your post! Identity protection only comes into play when primary Credentials are successful. Smart lockout is the closest solution to prevent first-factor/primary credentials and detect risk at that level. Using smart lockout, if primary credentials are successful, we detect a risk, and there is a policy to change the password, we will request that to happen or block the user.
Let me know if this helps and if you have further questions.
If the information addressed your question, please Accept the answer. This will help us as well as others in the community who may be researching similar information.