question

Faha-7530 avatar image
0 Votes"
Faha-7530 asked ShwetaMathur answered

Conditional Access: User based Risk Policy

Hi Guys
We currently have a policy in place that forces all high risk users to submit a recurring MFA request (sign-in frequency 1h).
Now, there are some users who are not classified as high risk users in identity protection, but they are still affected by the policy.
How exactly does the conditional access policy evaluate this risk status? And how can such affected users, who are apparently considered high risk users, be resolved?
Best regards and thank you for the answer!

azure-ad-conditional-accessazure-ad-identity-protection
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

ShwetaMathur avatar image
0 Votes"
ShwetaMathur answered

Hi @Faha-7530,

Thanks for reaching out and apologies for delay in response.

I understand that you are facing issue where all the users are affected by conditional access policy to enforce MFA request whereas policy has been setup for high-risk users only.

There might be reason those users are not configured as high-risk users in Identity protection but due to many factors described here put them in high-risk users and as conditional access policy has been configured for high-risk users enforcing MFA on those users.

Any identified suspicious actions in user accounts are come under risks and there are many factors to evaluate the risk as mentioned in documentation.

You can either apply policy to self-remediate those users who are affected by policy using Azure AD Multi-Factor Authentication (MFA) and self-service password reset (SSPR).

or exclude those users from the conditional access policy if those users have been evaluated no risk users.

190553-image1.png

Hope this will help.

Thanks,
Shweta


Please remember to "Accept Answer" if answer helped you.



image1.png (81.4 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.