Risky Users
This page lists the accounts Microsoft Entra ID Protection currently holds a risk assessment for, so a tenant's flagged users can be reviewed and cleared without opening the Entra portal. The table is sorted with the most recently updated risk first.
Table Details
The properties returned are for the Graph resource type riskyUser. For more information on the properties please see the Graph documentation.
Filters
Users at Risk
Accounts whose risk is still open and has not been acted on.
Dismissed Users
Accounts whose risk has been dismissed, either here or in the Entra portal.
Remediated Users
Accounts whose risk was resolved by the user meeting a remediation requirement, such as a self-service password reset or a risky sign-in policy.
Table Actions
Dismiss Risk
Marks the account's risk as dismissed, which tells Entra ID Protection the activity was legitimate and returns the account to a normal state.
Research Compromised Account
Opens the Compromise Remediation tab for the account, where the usual indicators of compromise are gathered in one place.
More Info
Opens the Extended Info flyout with the full details for the selected row.
Dismissing a risk closes it without changing anything about the account. It does not reset a password, revoke a session or remove whatever caused the detection, so an account that really is compromised stays compromised with its warning cleared. Investigate before dismissing, and remediate through the Compromise Remediation page or the Users list where the account turns out to be at risk.
Feature Requests / Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

