SOLVED

Azure AD identnty protection User and sign-in policy

Copper Contributor

Greetings,

 

As per Microsoft article https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-close-active-risk-... , there is an option mentioned to change password on the controls for user risk policy. But this control isn't appear to me. What is can see only allow access with MFA or Block access.

 

My second question: What is the difference between user risk policy and sign-in risk policy? i see both policies have the same options.

 

Regards,

 

Khaled El Gazzar

2 Replies
best response confirmed by Khaled Elgazzar (Copper Contributor)
Solution

It's explained in the document you linked to. Think of the sign-in policy as real-time detection based on the parameters of the current login attempt, and the risk policy as adding on top of that, with other signals. The change password control is only available for the risk policy.

Many thanks Vasil for clarification.

Regards,
1 best response

Accepted Solutions
best response confirmed by Khaled Elgazzar (Copper Contributor)
Solution

It's explained in the document you linked to. Think of the sign-in policy as real-time detection based on the parameters of the current login attempt, and the risk policy as adding on top of that, with other signals. The change password control is only available for the risk policy.

View solution in original post