Can't clear user risk for deleted user

Anonymous
2022-04-11T15:19:22.81+00:00

We recently purchased Azure Premium P2 licenses. I just started going through the risk detections....its a lot but most of them are old. One issue I have run into is that I can't clear the user risk for accounts that have been deleted. One in particular left the org almost 4 years ago. Whenever I try to clear the risk though, I get an error that Azure was unable to initiate the dismissal and to try again in a few minutes.

Is there anything I can do to get around this?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2022-04-11T23:50:15.633+00:00

    Hi @Anonymous ,

    I understand that you are seeing risk detections for deleted users and are unable to clear them.

    This scenario is covered in our documentation here:

    Deleted users
    It isn't possible for administrators to dismiss risk for users who have been deleted from the directory. To remove deleted users, open a Microsoft support case.

    One possible workaround would be to exclude the users from the user risk policy to bypass the policy block.

    I'll leave more information in a private comment about how to get around this issue via support case.

    Marilee

    -

    If this answer helps resolve your question, please remember to "mark as answer" so that others in the community with similar questions can more easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.