Microsoft Entra ID Protection Weekly Digest reports drastically higher number of risky sign-ins than Microsoft Entra ID Identity Protection

Tilman Schmidt 120 Reputation points
2025-04-01T15:54:18.8166667+00:00

The number of "New risky sign-ins detected (in real-time)" reported in the Microsoft Entra ID Protection Weekly Digest for my tenant has jumped from 78 last week to 8498 this week.

I was of course alarmed and tried to investigate where this exorbitant number might originate.

However in the Microsoft Entra admin center I find no trace of this drastic rise in risky sign-ins.

The Identity Protection > Report > Risky sign-ins page shows the usual peaceful trickle of <10 events per day, all false positives as usual.

Where would I look for the source of that alarming number in the weekly digest mail?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Goutam Pratti 6,170 Reputation points Microsoft External Staff Moderator
    2025-04-04T13:08:43.67+00:00

    Hello @Tilman Schmidt ,

    You can drop the investigation because this is an Expected behavior. The real-time data displayed in the portal is dynamically calculated, meaning the numbers in the weekly digest may not exactly match what you see in the portal at a later time. The real-time detection process analyzes signals directly from the request pipeline, while the weekly digest numbers are derived from raw signals rather than aggregated data.

    Additionally, if any sign-ins were incorrectly flagged as risky (false positives), Microsoft's machine learning algorithms may have automatically remediated or dismissed them. As a result, these sign-ins would no longer appear in the portal.

    That's why you'll observe such differences when compares with weekly email and Azure Portal data.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.