What Is Microsoft Entra ID Protection and What Benefits Does It Provide?
Cybercriminals do not always need to break through a firewall or infect a computer with malware.
Sometimes they simply log in.
A stolen Microsoft 365 username and password can potentially give an attacker access to email, OneDrive, SharePoint, Teams and other business information. That is why identity protection has become such an important part of modern cybersecurity.
Microsoft Entra ID Protection is designed to help organisations detect, investigate and respond to identity-based risks.
It continuously evaluates sign-ins and user activity for indicators that an account or authentication attempt may be suspicious. Those risk signals can then be used with Microsoft Entra Conditional Access to challenge, restrict or block access.
Microsoft describes Entra ID Protection as a service that helps organisations detect, investigate and remediate identity-based risks, while feeding those risks into Conditional Access or security monitoring platforms.
For businesses using Microsoft 365, that can provide an important extra layer of protection against compromised accounts.
What Happened to Azure AD Identity Protection?
If you have seen the term Azure AD Identity Protection, it refers to the same underlying technology under Microsoft's older naming.
Azure Active Directory was renamed Microsoft Entra ID, and the current product name is therefore Microsoft Entra ID Protection.
Older documentation, technical articles and even some administrators may still refer to Azure AD Identity Protection, but businesses planning or reviewing their Microsoft 365 security should use the newer Entra terminology.
That makes it easier to follow Microsoft's current documentation and administration interfaces.
How Does Entra ID Protection Work?
Traditional authentication asks a relatively simple question:
Did the user enter the correct credentials?
Identity Protection asks additional questions.
For example:
- Is this sign-in behaving unusually?
- Has Microsoft detected signals that suggest the account may be compromised?
- Is the sign-in coming from infrastructure associated with suspicious activity?
- Does the behaviour differ significantly from what is normal for this user?
- Is there evidence that the user's credentials may have been exposed?
Microsoft combines a wide range of risk detections to identify suspicious sign-ins and users. These detections can occur in real time or after additional analysis.
The result is a risk assessment that administrators and Conditional Access policies can use when deciding whether access should be allowed.
What Is Sign-In Risk?
Sign-in risk represents the likelihood that a particular authentication attempt is not being performed by the legitimate account owner.
Imagine an employee successfully signs in with the correct password.
That does not necessarily prove the person signing in is the employee.
If the account has been compromised, the attacker may know the password too.
Entra ID Protection can evaluate the circumstances surrounding that authentication attempt and assign a risk level.
Microsoft defines sign-in risk as the likelihood that an authentication request is not authorised by the identity owner.
A business can then use Conditional Access to determine what happens when elevated sign-in risk is detected.
For example, a policy could require additional authentication or block access depending on the organisation's security design.
What Is User Risk?
User risk looks at the account rather than one individual login.
It represents the likelihood that the user's identity itself has been compromised.
This is important because one suspicious sign-in may be part of a wider problem.
If Microsoft receives signals suggesting that an account has been exposed or taken over, that user can be marked as risky.
Administrators can then investigate the account, review detections and take remedial action.
Microsoft provides dedicated risky-user reporting as part of Entra ID Protection, with full access to the relevant data requiring appropriate P2 licensing.
What Sort of Activity Can Identity Protection Detect?
Microsoft Entra ID Protection can generate a variety of risk detections.
The exact list can change as Microsoft's detection capabilities evolve, but the service is designed to identify behaviour that may indicate an account or sign-in is suspicious.
Examples can include signals associated with:
- leaked credentials
- anonymous or suspicious IP addresses
- unfamiliar sign-in characteristics
- unusual authentication behaviour
- atypical travel patterns
- suspicious token activity
- other anomalous account behaviour
No single detection should automatically be interpreted as proof that an account has been hacked.
Risk detections are signals that need to be assessed within the wider security context.
This is why automated controls and administrator investigation are both important.
Why Passwords Alone Are Not Enough
A password can be:
- phished
- reused
- guessed
- stolen
- leaked in an unrelated breach
- entered into a fake Microsoft 365 login page
Once an attacker has valid credentials, a traditional login system may see nothing unusual.
That is one reason modern identity security focuses on much more than passwords.
Good protection should combine several controls, including:
- multi-factor authentication
- Conditional Access
- device management
- secure administrator accounts
- sign-in monitoring
- risk detection
- endpoint security
- user awareness training
Entra ID Protection adds another source of intelligence to that overall security model.
How Conditional Access Fits In
Conditional Access is one of the most important parts of Microsoft's identity-security platform.
It allows businesses to create policies that consider conditions surrounding an access request before deciding whether access should be granted.
Those conditions can include things such as:
- user identity
- device state
- application
- location
- sign-in risk
- user risk
Risk-based Conditional Access uses Entra ID Protection signals as part of that decision-making process.
Microsoft confirms that sign-in-risk and user-risk Conditional Access policies require Entra ID Protection, which is an Entra ID P2 capability.
This means businesses can move beyond a simple rule of:
Correct password = access granted.
Instead, access can become adaptive.
A Practical Example
Imagine one of your employees signs in to Microsoft 365 every weekday from a managed laptop in Yorkshire.
One evening, the account is used in circumstances Microsoft considers significantly more risky.
Rather than automatically granting full access simply because the correct password was entered, Entra ID Protection can contribute a risk signal.
A Conditional Access policy can then respond appropriately.
Depending on the configuration, that could mean additional authentication is required or access is restricted.
This is particularly useful because the organisation does not need an administrator manually watching every login in real time.
The security policy can react automatically.
Automatic Remediation
One of the strongest benefits of Entra ID Protection is the ability to combine risk detection with automated remediation.
Instead of merely generating an alert that someone needs to investigate tomorrow, the organisation can create policies that respond while the activity is taking place.
This can significantly shorten the window available to an attacker.
Microsoft supports risk-based Conditional Access policies that use sign-in and user risk to automate security responses.
Automation does not remove the need for human oversight.
Security teams should still investigate risky users, understand why detections occurred and determine whether further action is required.
But automated response can help contain risk sooner.
The Important October 2026 Change
There is an important change businesses need to know about.
Microsoft is retiring the legacy user-risk and sign-in-risk policies configured directly within Entra ID Protection on 1 October 2026.
If your organisation still uses those older policies, Microsoft recommends moving them to Conditional Access.
This does not mean risk-based identity protection is disappearing.
It means Microsoft is consolidating the way organisations configure those protections.
Businesses should therefore review their Entra configuration now rather than waiting until October.
If an IT provider originally configured your Microsoft 365 tenant several years ago, it is worth checking whether legacy Identity Protection policies are still in use.
Why Move to Conditional Access?
Microsoft's current guidance is clear that risk-based policies should be implemented through Conditional Access.
This creates a more consistent framework for access decisions because identity risk can be combined with other conditions.
For example, an organisation could design policies around:
- sign-in risk
- user risk
- managed devices
- privileged accounts
- sensitive applications
- MFA requirements
That gives administrators far greater control than managing risk policies as a completely separate feature.
What Licensing Do You Need?
Licensing is an important consideration.
Full Microsoft Entra ID Protection capabilities require Microsoft Entra ID P2 or Microsoft Entra Suite licensing.
Risk-based Conditional Access using user risk or sign-in risk is also an Entra ID P2 capability.
This means businesses should not assume that buying any Microsoft 365 licence automatically gives them the full Identity Protection feature set.
Some Microsoft plans include Entra ID P1 rather than P2.
The correct licensing depends on:
- which security controls are required
- which users need protecting
- the organisation's wider Microsoft 365 plan
- regulatory or compliance requirements
- the level of identity risk the business wants to manage
A licensing review can therefore be just as important as the technical configuration.
What Can Administrators Investigate?
Entra ID Protection provides reporting around risky users, risky sign-ins and individual risk detections.
Administrators can investigate suspicious activity and determine whether the event appears genuine or malicious.
Microsoft's current administration workflow includes dedicated Risky sign-ins and Risky users views within the Entra admin centre.
This can help answer questions such as:
- Which account was affected?
- When did the suspicious activity occur?
- What risk was detected?
- Has the account subsequently been secured?
- Does the activity require further investigation?
That visibility becomes particularly useful during a suspected Microsoft 365 account compromise.
Identity Protection and Microsoft 365
Identity security matters because one Microsoft account can provide access to a large amount of business information.
Depending on the user's permissions, a compromised account could potentially expose:
- Exchange Online email
- OneDrive files
- SharePoint documents
- Teams conversations
- calendars
- customer information
- internal company data
- connected SaaS applications
Privileged administrator accounts create even greater risk.
That is why businesses should treat identity security as a core part of Microsoft 365 security rather than an optional extra.
Identity Protection Does Not Replace MFA
Identity Protection and MFA solve different problems.
MFA makes it harder for an attacker to use stolen credentials.
Identity Protection helps identify suspicious behaviour and account risk.
Conditional Access connects those security controls together.
A mature configuration might therefore use:
- MFA to strengthen authentication.
- Identity Protection to detect risk.
- Conditional Access to decide how the organisation responds.
- Endpoint management to assess device security.
- Monitoring to investigate suspicious events.
Layering those controls provides much stronger protection than relying on any one feature.
It Also Does Not Replace Good Administration
Technology cannot compensate for poor Microsoft 365 administration.
Businesses should still:
- remove former employees promptly
- restrict administrator privileges
- use separate admin accounts
- review guest users
- monitor external sharing
- block legacy authentication
- keep devices patched
- manage third-party application access
- review security alerts
Identity Protection should sit within a wider Microsoft 365 security strategy.
Who Should Consider Entra ID Protection?
Risk-based identity security is particularly worth considering for organisations that:
- store sensitive information in Microsoft 365
- have remote or hybrid workers
- operate in regulated industries
- handle customer financial information
- have privileged administrators
- are frequently targeted by phishing
- need stronger Conditional Access controls
- want better visibility into compromised accounts
It can be particularly valuable where the impact of an account takeover would be significant.
Common Mistake: Buying P2 but Not Configuring It
A surprisingly common problem with Microsoft 365 security is paying for advanced functionality without actually using it.
An organisation may have licensing that provides Entra ID Protection but still have:
- no risk-based Conditional Access policies
- weak MFA enforcement
- old administrator accounts
- unmanaged devices
- ignored risky-user alerts
Security features provide value only when they are correctly configured and monitored.
That is why Microsoft 365 security reviews should look at configuration rather than simply asking which licences are being purchased.
How Hamilton Group Can Help
Hamilton Group can help businesses review and strengthen their Microsoft 365 identity security.
This can include:
- Microsoft Entra ID reviews
- Microsoft Entra ID Protection
- Conditional Access
- multi-factor authentication
- risky-user and risky-sign-in investigation
- administrator-account security
- Microsoft Intune
- Microsoft Defender
- Microsoft 365 security reviews
- licence reviews
- migration from legacy risk policies
- wider Microsoft 365 management
With the legacy Identity Protection risk policies being retired on 1 October 2026, now is a sensible time to check whether your tenant is using Microsoft's current Conditional Access approach.
If you are unsure whether Entra ID Protection is configured correctly — or whether you even have the necessary licensing — Hamilton Group can review your Microsoft 365 environment and identify gaps.
Visit hgmssp.com or call 0330 043 0069 to speak with Hamilton Group.