Forum Discussion
NoobieInfoSec
Sep 01, 2022Copper Contributor
Risky Sign-in Report - Where to see or adjust the settings?
We are seeing some inconsistencies with our Risky Sign-in reports. For example, we'll have multiple users who travel over seas, logging in from foreign IP addresses for the first time, and some will...
- Sep 02, 2022I am not an Azure AD IP expert, but did you look at our documentation? https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies
There is also a YouTube video in this article.
For reports I found this page: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-investigate-risk
If the simulation from earlier doesn't help, I honestly would suggest to open a support ticket to see why some users are flagged, whilst others are not.
HeikeRitter
Microsoft
Sep 01, 2022This falls under Azure AD IP - There’s an article about simulating some of the behaviors to test -> https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-simulate-risk
Can you have a look if that works for you?
Can you have a look if that works for you?
NoobieInfoSec
Sep 01, 2022Copper Contributor
Sure, I will test these out - thank you!
Is there a way for us to configure how risky sign in works? Like turn certain features ON or OFF?
Is there a way for us to configure how risky sign in works? Like turn certain features ON or OFF?
- HeikeRitterSep 02, 2022
Microsoft
I am not an Azure AD IP expert, but did you look at our documentation? https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies
There is also a YouTube video in this article.
For reports I found this page: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-investigate-risk
If the simulation from earlier doesn't help, I honestly would suggest to open a support ticket to see why some users are flagged, whilst others are not.