StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 2: Respond to security incidents

Microsoft Entra ID Protection: risky users and sign-ins, confirm user compromised, revoking sessions; MFA fatigue response

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Microsoft Entra ID Protection uses signals from Microsoft's identity systems to judge how likely it is that a sign-in or an account is compromised. It has two kinds of risk. Sign-in risk is the probability that a particular sign-in was not made by the account owner, for example from an anonymous IP address, an unfamiliar location, or a token that looks replayed. User risk is the probability that the account itself is compromised, for example because its credentials were found leaked, or because of a pattern of risky sign-ins. Risk levels are low, medium and high. Some detections are real-time, calculated during sign-in, and others are offline, calculated afterward.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan