@Tilman Schmidt , you figured out the correct answer yourself in your reply on Apr 4, 2025, 2:41 a.m., but I'll post it here as a separate answer.
TL;DR: Some risky sign-in (real-time) events may have a Risk State = none, and the only way to view those is to deselect all of the Risk State filters.
All of the gaslighting answers from Microsoft employees are wrong; "risky sign-in (in real-time)" events that were immediately auto-remediated or that were dismissed shortly after detection are still visible in the Entra admin center Identity Protection "Risky sign-ins" blade when the filters are set correctly.
Explanation:
The events contributing to the “New risky sign-ins detected (in real-time)” count in the weekly digest are those whose Risk level (real-time) = Low / Medium / High. The values of Risk State could be anything (At risk, Confirmed compromised, Confirmed safe, Dismissed, Remediated) or nothing. The last word here is critical.
The natural assumption is that selecting all available Risk State values will display all risky sign-ins. However, this is not the case. Sign-ins whose Risk State is "None" are excluded whenever any (or all) Risk State filter value is selected. Misleadingly, there is no "None" option available in the filter. So, the only way to view sign-ins whose Risk State = none is to deselect all of the Risk State filters.
Once you do that that and also filter the Risk level (real-time) to include all values (Low, Medium, High) and you should see all the events the digest included in its count.
It may also be helpful to customize the columns and enable display of the “Risk level (real-time)” column. This doesn't affect filtering, but since you're filtering on that column, it's useful to actually see it column.
If anyone from Microsoft reads this, I'd like to request that they update the UI of the Risk State filter to include "None" as a selectable value. And it would also be nice to have the “Risk level (real-time)” column shown by default.