{"id":16398,"date":"2020-08-12T06:37:27","date_gmt":"2020-08-12T06:37:27","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=16398"},"modified":"2022-03-14T05:32:10","modified_gmt":"2022-03-14T05:32:10","slug":"configuring-and-enabling-risk-policies","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/","title":{"rendered":"Configuring and Enabling Risk policies"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-500-microsoft-azure-security-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-500 Tutorials<\/a><\/p>\n\n\n\n<p>In this tutorial, we will learn about configuring and enabling risk policies like Sign-in risk policy and User risk policy. Both policies work to automate the response to risk detections in your environment and allow users to self-remediate when risk is detected.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Prerequisites<\/strong><\/h6>\n\n\n\n<p>If your organization wants to give access to users for self-remediation when risks are detected, users must be registered for both self-service password reset and Azure Multi-Factor Authentication. However, we recommend enabling the combined security information registration experience for the best experience. As allowing users for self-remediation gets them back to a productive state without needing administrator intervention. But, the Administrators can still see these events and even investigate them after the fact.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Choosing acceptable risk levels<\/strong><\/h5>\n\n\n\n<p>Organizations should decide the risk level, as they are willing to accept balancing user experience and security posture. However, Microsoft&#8217;s recommendation is to set the user risk policy threshold to High and the sign-in risk policy to Medium and above.<\/p>\n\n\n\n<p>Choosing a High threshold decreases the number of times a policy triggers and minimizes the impact to users. However, it removes low and medium risk detections from the policy that may not block an attacker from exploiting a compromised identity. And, selecting a Low threshold will introduce additional user interrupts. But it will increase the security posture.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Exclusions<\/strong><\/h4>\n\n\n\n<p>Excluding users such as emergency access or break-glass administrator accounts is possible with any of the policies. Furthermore, companies should determine if additional accounts should be excluded from certain restrictions based on how they are utilised. All exclusions must be reviewed on a regular basis to ensure that they are still valid. However, to reduce false positives, Identity Protection leverages preset trustworthy network locations in some risk detections.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-security-technologies-az-500-free-practice-test\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-7.png\" alt=\"AZ_500 online course\"\/><\/a><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Enable policies<\/strong><\/h4>\n\n\n\n<p>For enabling the user risk and sign-in risk policies complete the following steps.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, navigate to the Azure portal.<\/li><li>Secondly, browse to Azure Active Directory &gt; Security &gt; Identity Protection &gt; Overview.<\/li><li>Then, Select User risk policy.<\/li><\/ul>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Under Assignments<\/strong><\/li><\/ol>\n\n\n\n<p><strong>Users<\/strong> &#8211; In this, choose All users or Select individuals and groups if limiting your rollout.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Here you have the option to choose to exclude users from the policy.<\/li><\/ol>\n\n\n\n<p><strong>Conditions<\/strong> &#8211; In this, user risk Microsoft&#8217;s recommendation is to set this option to High.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>b. Under Controls<\/strong><\/p>\n\n\n\n<p><strong>Access<\/strong> &#8211; In this, Microsoft&#8217;s recommendation is to Allow access and Require password change.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>c. Enforce Policy &#8211; On<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>d. Save<\/strong> &#8211; This action will return you to the Overview page.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>After that, Select Sign-in risk policy.<\/li><\/ul>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Under Assignments<\/strong><\/li><\/ol>\n\n\n\n<p><strong>Users<\/strong> &#8211; In this, select All users or individuals and groups if have limiting rollout.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Here you have the option to choose to exclude users from the policy.<\/li><\/ol>\n\n\n\n<p><strong>Conditions<\/strong> &#8211; In this, sign-in risk Microsoft&#8217;s recommendation for setting this option to Medium and above.<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li><strong>Under Controls<\/strong><\/li><\/ol>\n\n\n\n<p><strong>Access <\/strong>&#8211; This has Microsoft&#8217;s recommendation for Allowing access and Require multi-factor authentication.<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li><strong>Enforce Policy &#8211; On<\/strong><\/li><li><strong>Save<\/strong><\/li><\/ol>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-security-technologies-az-500-practice-exam\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"961\" height=\"150\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-500-online-course-6.png\" alt=\"risk policies concept in Az-500 Online course\" class=\"wp-image-16403\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-500-online-course-6.png 961w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-500-online-course-6-750x117.png 750w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-right\"><strong>Reference: <\/strong><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/identity-protection\/howto-identity-protection-configure-risk-policies\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Documentation<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-500-microsoft-azure-security-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-500 Tutorials<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Go back to AZ-500 Tutorials In this tutorial, we will learn about configuring and enabling risk policies like Sign-in risk policy and User risk policy. Both policies work to automate the response to risk detections in your environment and allow users to self-remediate when risk is detected. Prerequisites If your organization wants to give access&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-16398","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials<\/title>\n<meta name=\"description\" content=\"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials\" \/>\n<meta property=\"og:description\" content=\"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-14T05:32:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-7.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/\",\"name\":\"Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2020-08-12T06:37:27+00:00\",\"dateModified\":\"2022-03-14T05:32:10+00:00\",\"description\":\"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Configuring and Enabling Risk policies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials","description":"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/","og_locale":"en_US","og_type":"article","og_title":"Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials","og_description":"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2022-03-14T05:32:10+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-7.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/","name":"Configuring and Enabling Risk policies | Microsoft Azure AZ-500 Tutorials","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2020-08-12T06:37:27+00:00","dateModified":"2022-03-14T05:32:10+00:00","description":"Enhance your skills by learning about configuring and enabling risk policies using Microsoft Azure AZ-500 online course Now!","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-and-enabling-risk-policies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"Configuring and Enabling Risk policies"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/16398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=16398"}],"version-history":[{"count":6,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/16398\/revisions"}],"predecessor-version":[{"id":52748,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/16398\/revisions\/52748"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=16398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=16398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=16398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}