If a user has activity that raises their risk level, but the identity protection policies (user & sign-in) in place effectively block access - does this mean the attempted access would have otherwise been successful? In other words - has the user's password been compromised and needs reset?
Trying to figure out if it's necessary to reset the user's password for each increase in risk status. For example, all I see right now is a status of 'Failure' with a reason "Access policy does not allow token issuance." - doesn't tell me much regarding the finer login details.