Forum Discussion
Segmentation For Risky User/Risky Sign In Policy
- MatejKlemencicBrass Contributor
Hello egrizzly365
To apply different Risks policies to various user groups (scopes), you should manage them with Conditional Access Policies. By doing this, you can tailor controls for users based on their roles within the company and manage exclusions more effectively. Check this article Risk policies - Microsoft Entra ID Protection | Microsoft Learn
- egrizzly365Copper Contributor
Thanks MatejKlemencic. I meant how do you go about determining which groups will get segmented? Meaning, if there are 3 users James Dean, John Doe, and Jane Doe with different job roles how do you determine which job roles get put into a higher or lower risk segment?- MatejKlemencicBrass Contributor
Hi egrizzly365
I don't use multiple policies for different groups. Instead, I configure two conditional access policies: one for risky sign-ins and another for risky users. In these policies, I block access if the risk level is medium or high. For low-risk levels, I only notify administrators and don't implement any blocking actions. Additionally, I set up an exclusion rule to prevent access from being blocked if a user connects from a trusted device (such as an Intune compliant device) or a trusted site. This approach helps avoid false positives from blocking legitimate sign-ins. Besides blocking, you can also choose different actions, such as requiring MFA or a password change.