Microsoft Entra - Users at high risk - Unexpected error

BEBS Admin 20 Reputation points
2025-04-30T15:17:36.18+00:00

Does anyone know why this message appears and what can be done about it?Screenshot 2025-04-30 165823

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,563 questions
{count} votes

Accepted answer
  1. Bandela Siri Chandana 2,890 Reputation points Microsoft External Staff Moderator
    2025-04-30T17:56:36.2466667+00:00

    Hi @BEBS Admin
    I hope @Jose Benjamin Solis Nolasco information was helpful. In addition,
    A risk detection with risk level High signifies that Microsoft is highly confident that the account is compromised.
    Some detections, like Leaked Credentials and Verified Threat Actor IP are always delivered as high risk.

    1. Review the ID Protection dashboard to visualize number of attacks, number of high-risk users and other important metrics based on detections in your environment.
    2. Review the Impact analysis workbook to understand the scenarios where risk is evident in your environment and risk-based access policies should be enabled to manage high-risk users and sign-ins.

    Recommended action: Set up risk-based Conditional Access policies to require password reset, perform MFA, or block access for all high-risk sign-ins.
    You can allow users to self-remediate their sign-in risks and user risks by setting up risk-based policies. If users pass the required access control, such as multifactor authentication or secure password change, then their risks are automatically remediated. The corresponding risk detections, risky sign-ins, and risky users are reported with the risk state Remediated instead of At risk.

    Administrators can remediate using the following options:

    • Set up risk-based policies to allow users to self-remediate their risks.
    • Manually reset their password.
    • Dismiss their user risk.

    Remediate in Microsoft Defender for Identity.

    Follow the document for more information: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-remediate-unblock

    Hope this helps. Do let us know if you have any further queries.
    If this answers your query, do click `Accept Answer` and `Yes`


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.