Identity protection: users at risk detected alerts

%3CLINGO-SUB%20id%3D%22lingo-sub-1719342%22%20slang%3D%22en-US%22%3EIdentity%20protection%3A%20users%20at%20risk%20detected%20alerts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1719342%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3Eafter%20the%20new%20version%20of%20Identity%20Protection%20email%20alert%20configuration%20GUI%20I%20can't%20understand%20how%20it%20works%20(and%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fidentity-protection%2Fhowto-identity-protection-configure-notifications%23configure-users-at-risk-detected-alerts%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E%20is%20not%20updated%20and%20unclear).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20confiuguration%20page%20gives%20this%20advice%3A%3C%2FP%3E%3CP%3E%3CFONT%20size%3D%222%22%3E%22%3CSPAN%3EUsers%20in%20the%20Global%20administrator%2C%20Security%20administrator%2C%20or%20Security%20reader%20roles%20are%20automatically%20added%20to%20this%20list.%20We%20attempt%20to%20send%20emails%20to%20the%20first%2020%20members%20of%20each%20role.%20If%20a%20user%20is%20enrolled%20in%20PIM%20to%20elevate%20to%20one%20of%20these%20roles%20on%20demand%20then%20they%20will%20only%20receive%20emails%20if%20they%20are%20elevated%20at%20the%20time%20the%20email%20is%20sent.%22%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20what%20I%20can%20see%20in%20my%20customer's%20tenants%20are%20a%20bit%20different%3A%3C%2FP%3E%3CUL%3E%3CLI%3EOne%20shows%20a%20partial%20list%20of%20GA%20and%20I%20can%20disable%26nbsp%3Bthe%20ones%20I%20don't%20want%20to%20send%20alerts.%26nbsp%3B%3C%2FLI%3E%3CLI%3EAnother%20one%20is%20empty%20(but%20they%20have%20a%20lot%20of%20GA)%20and%20only%20a%20few%20receive%20alerts.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eaccording%20to%20which%20criteria%20are%20the%20emails%20sent%3F%20to%20the%20first%2020%20of%20each%20role%20in%20what%20order%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20help%20me%20to%20better%20understand%20this%20behaviour%3F%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3EMike%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1719342%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1719988%22%20slang%3D%22en-US%22%3ERe%3A%20Identity%20protection%3A%20users%20at%20risk%20detected%20alerts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1719988%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F227410%22%20target%3D%22_blank%22%3E%40Michele%20D'Angelantonio%3C%2FA%3E%26nbsp%3BHello%2C%20in%20this%20case%20I%20would%20like%20to%20suggest%20that%20you%20open%20up%20a%20%22GitHub%22%20as%20it%20has%20to%20do%20with%20the%20docs.%20Look%20at%20the%20bottom%20of%20the%20page%20you%20linked%20and%20click%20on%20%22This%20page%22%20to%20submit%20an%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22image.png%22%20style%3D%22width%3A%20200px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F222555i0476EFD0DBD90104%2Fimage-size%2Fsmall%3Fv%3D1.0%26amp%3Bpx%3D200%22%20title%3D%22image.png%22%20alt%3D%22image.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

after the new version of Identity Protection email alert configuration GUI I can't understand how it works (and the documentation is not updated and unclear).

 

The confiuguration page gives this advice:

"Users in the Global administrator, Security administrator, or Security reader roles are automatically added to this list. We attempt to send emails to the first 20 members of each role. If a user is enrolled in PIM to elevate to one of these roles on demand then they will only receive emails if they are elevated at the time the email is sent."

 

But what I can see in my customer's tenants are a bit different:

  • One shows a partial list of GA and I can disable the ones I don't want to send alerts. 
  • Another one is empty (but they have a lot of GA) and only a few receive alerts.

 

according to which criteria are the emails sent? to the first 20 of each role in what order?

 

Can someone help me to better understand this behaviour?

Thanks in advance

Mike

1 Reply

@Michele D'Angelantonio Hello, in this case I would like to suggest that you open up a "GitHub" as it has to do with the docs. Look at the bottom of the page you linked and click on "This page" to submit an issue.

 

image.png