Skip to main content

Azure Active Directory Identity Protection (Deprecated)

This Integration is part of the Azure Active Directory Identity and Access (Deprecated) Pack.#


This is a beta Integration, which lets you implement and test pre-release software. Since the integration is beta, it might contain bugs. Updates to the integration during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the integration to help us identify issues, fix them, and continually improve.


Use Microsoft Graph Identity and Access instead.

Gets information from the Azure Active Directory Identity Protection service. This integration was integrated and tested with the beta version of Azure Active Directory Identity Protection API.

Required Permissions#

To use this integration, the following permissions are required on the Azure app.

  • IdentityRiskEvent.Read.All
  • IdentityRiskyUser.ReadWrite.All
  • User.Read


Theres two ways to connect to the Azure Active Directory Identity Protection:

  1. Azure app flows:

    • Cortex XSOAR Azure app
    • Self Deployed Azure app

    Both of the flows use the device authorization grant flow

  2. Client credentials Client Credentials

Azure app flows#

Cortex XSOAR Azure app#

To use the Cortex XSOAR Azure app, use the default application ID 4ffef4a4-601f-4393-a789-432f3f3b8470 and fill in your subscription ID.

Self Deployed Azure app#

To use a self-deployed Azure app, add a new Azure App Registration in the Azure Portal

  1. The app must allow public client flows (which can be found under the Authentication section of the app).
  2. The app must be multi-tenant.
  3. The app should be granted the permissions listed in the required permissions section above.

Client Credentials Flow#

Follow these steps for a self-deployed configuration:

  1. To use a self-configured Azure application, you need to add a new Azure App Registration in the Azure Portal. To add the registration, refer to the following Microsoft article steps 1-8.
  2. In the instance configuration, select the client-credentials checkbox.
  3. Enter your Client/Application ID in the Application ID parameter.
  4. Enter your Client Secret in the Client Secret parameter.
  5. Enter your Tenant ID in the Tenant ID parameter.
  6. Run the azure-ad-auth-start command to test the connection and the authorization process.

Configure Azure Active Directory Identity Protection on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services.

  2. Search for Azure Active Directory Identity Protection.

  3. Click Add instance to create and configure a new integration instance.

    Application IDThe ID of the managed application.True
    Subscription IDThe Azure Active Directory subscription ID, found on the Azure Portal.True
    Azure Active Directory endpointThe Azure Active Directory endpoint associated with a national cloud.True
    Use Client Credentials Authorization FlowUse a self-deployed Azure application and authenticate using the Client Credentials flow.False
    Tenant IDTenant IDFalse
    Client SecretEncryption key given by the adminFalse
    Trust any certificate (not secure)When selected, certificates are not checked.False
    Use system proxy settingsWhen selected, runs the integration instance using a proxy server (https or http) that you defined in the server configuration.False
  4. Run the !azure-ad-auth-start command to start the connection process.

  5. Follow the instructions shown. The last of them should be running the !azure-ad-auth-complete command.

  6. Run the !azure-ad-auth-test command to validate the URLs, token, and connection.

Base Command#



There are no input arguments for this command.

Context Output#

There is no context output for this command.

Command Example#


Human Readable Output#

โœ… Success!


Run this command to start the authorization process and follow the instructions shown.

Base Command#



There are no input arguments for this command.

Context Output#

There is no context output for this command.

Command Example#


Human Readable Output#

Authorization instructions#

  1. To sign in, use a web browser to open the page and enter the code EXAMPLE-CODE to authenticate.
  2. Run the !azure-ad-auth-complete command in the War Room.


Run this command to complete the authorization process. This should be used after running the azure-ad-auth-start command.

Base Command#



There are no input arguments for this command.

Context Output#

There is no context output for this command.

Command Example#


Human Readable Output#

โœ… Authorization completed successfully.


Run this command if for some reason you need to rerun the authentication process.

Base Command#



There are no input arguments for this command.

Context Output#

There is no context output for this command.

Command Example#


Human Readable Output#

Authorization was reset successfully. Run !azure-ad-auth-start to start the authentication process.


Retrieve the properties of a collection of riskDetection objects.

Required Permissions#


Base Command#



Argument NameDescriptionRequired
idUnique ID of the risk detection.Optional
user_idUnique ID of the user.Optional
user_principal_nameThe user principal name (UPN) of the user.Optional
countryThe country or region of the activity. For example, US or UK. For further details, see
filter_expressionA custom query in OData syntax. Using this overrides all arguments, except for next_link. For more details, see
limitNumber of results to provide. Default is 50.Optional
next_linkA link that specifies a starting point for subsequent calls. Using this argument overrides all other arguments.Optional

Context Output#

AADIdentityProtection.Risks.idstringUnique ID of the risk detection.
AADIdentityProtection.Risks.requestIdstringThe ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in.
AADIdentityProtection.Risks.correlationIdstringCorrelation ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in.
AADIdentityProtection.Risks.riskEventTypestringThe type of risk event detected. The possible values are unlikelyTravel, anonymizedIPAddress, maliciousIPAddress, unfamiliarFeatures, malwareInfectedIPAddress, suspiciousIPAddress, leakedCredentials, investigationsThreatIntelligence, generic,adminConfirmedUserCompromised, mcasImpossibleTravel, mcasSuspiciousInboxManipulationRules, investigationsThreatIntelligenceSigninLinked, maliciousIPAddressValidCredentialsBlockedIP, and unknownFutureValue.
AADIdentityProtection.Risks.riskTypestringDeprecated. Use riskEventType instead. List of risk event types.
AADIdentityProtection.Risks.riskLevelstringRisk level of the detected risky user. The possible values are low, medium, high, hidden, none, and unknownFutureValue.
AADIdentityProtection.Risks.riskStatestringState of the user's risk. The possible values are none, confirmedSafe, remediated, dismissed, atRisk, confirmedCompromised, and unknownFutureValue.
AADIdentityProtection.Risks.riskDetailstringReason why the user is considered a risky user. The possible values are limited to none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, adminConfirmedSigninCompromised, hidden, adminConfirmedUserCompromised, and unknownFutureValue.
AADIdentityProtection.Risks.sourcestringSource of the risk detection. For example, activeDirectory.
AADIdentityProtection.Risks.detectionTimingTypestringTiming of the detected risk (real-time/offline). The possible values are notDefined, realtime, nearRealtime, offline, and unknownFutureValue.
AADIdentityProtection.Risks.activitystringIndicates the activity type the detected risk is linked to. The possible values are signin, user, and unknownFutureValue.
AADIdentityProtection.Risks.tokenIssuerTypestringIndicates the type of token issuer for the detected sign-in risk. The possible values are AzureAD, ADFederationServices, and unknownFutureValue.
AADIdentityProtection.Risks.ipAddressstringProvides the IP address of the client from where the risk occurred.
AADIdentityProtection.Risks.location.citystringCity of the sign-in.
AADIdentityProtection.Risks.location.countryOrRegionstringCountry or region of the sign-in.
AADIdentityProtection.Risks.location.geoCoordinates.latitudestringLatitude of the sign-in.
AADIdentityProtection.Risks.location.geoCoordinates.longitudestringLongitude of the sign-in.
AADIdentityProtection.Risks.location.statestringState of the sign-in.
AADIdentityProtection.Risks.activityDateTimestringDate and time that the risky activity occurred. The DateTimeOffset type represents date and time information using the ISO 8601 format and is always in UTC time.
AADIdentityProtection.Risks.detectedDateTimestringDate and time that the risk was detected. The DateTimeOffset type represents date and time information using the ISO 8601 format and is always in UTC time.
AADIdentityProtection.Risks.lastUpdatedDateTimestringDate and time that the risk detection was last updated. The DateTimeOffset type represents date and time information using the ISO 8601 format and is always in UTC time.
AADIdentityProtection.Risks.userIdstringUnique ID of the user.
AADIdentityProtection.Risks.userDisplayNamestringRisky user display name.
AADIdentityProtection.Risks.userPrincipalNamestringRisky user principal name.
AADIdentityProtection.Risks.additionalInfostringAdditional information associated with the risk detection in JSON format.

Command Example#


Context Example#

"AADIdentityProtection": {
"Risks": [
"activity": "signin",
"activityDateTime": "2021-04-25T09:00:40.7780969Z",
"additionalInfo": "[{\"Key\":\"userAgent\",\"Value\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36\"}]",
"correlationId": "271ac223-695b-418e-85b3-7809070ee33e",
"detectedDateTime": "2021-04-25T09:00:40.7780969Z",
"detectionTimingType": "realtime",
"id": "86a45315157fb75c3a6e0936ef854c139df99bdfbde4bd7e7f1bc685c3638908",
"ipAddress": "",
"lastUpdatedDateTime": "2021-05-23T08:20:41.9161522Z",
"location": {
"city": "San Jose",
"countryOrRegion": "US",
"geoCoordinates": {
"latitude": 37.33053,
"longitude": -121.8382
"state": "California"
"requestId": "86b6e4a1-25cb-40c7-af2b-9e79c6106000",
"riskDetail": "userPerformedSecuredPasswordChange",
"riskEventType": "unfamiliarFeatures",
"riskLevel": "low",
"riskState": "remediated",
"riskType": "unfamiliarFeatures",
"source": "IdentityProtection",
"tokenIssuerType": "AzureAD",
"userDisplayName": "John Doe",
"userId": "3fa9f28b-eb0e-463a-ba7b-8089fe9991e2",
"userPrincipalName": ""
"activity": "signin",
"activityDateTime": "2021-04-28T11:40:11.333738Z",
"additionalInfo": "[{\"Key\":\"userAgent\",\"Value\":\"python-requests/2.18.4\"}]",
"correlationId": "6f74b0f4-dabc-49af-aa87-3aaba042baba",
"detectedDateTime": "2021-04-28T11:40:11.333738Z",
"detectionTimingType": "realtime",
"id": "c0e94938cddbb849ef64dbb6a98189ab3d93cdec4c4f95923ac935a91486def2",
"ipAddress": "",
"lastUpdatedDateTime": "2021-05-23T08:20:29.027631Z",
"location": {
"city": "Frankfurt Am Main",
"countryOrRegion": "DE",
"geoCoordinates": {
"latitude": 50.1109,
"longitude": 8.6821
"state": "Hessen"
"requestId": "64b01b65-25fa-4811-b4cd-411c9accc000",
"riskDetail": "userPerformedSecuredPasswordChange",
"riskEventType": "unfamiliarFeatures",
"riskLevel": "low",
"riskState": "remediated",
"riskType": "unfamiliarFeatures",
"source": "IdentityProtection",
"tokenIssuerType": "AzureAD",
"userDisplayName": "John Doe",
"userId": "3fa9f28b-eb0e-463a-ba7b-8089fe9991e2",
"userPrincipalName": ""

Human Readable Output#

Risks (6 results)#

User IDUser Principal NameUser Display NameIP AddressDetected Date TimeActivityActivity Date TimeAdditional InfoCorrelation IDDetection Timing TypeIDLast Updated Date TimeLocationRequest IDRisk DetailRisk Event TypeRisk LevelRisk StateRisk TypeSourceToken Issuer Type
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe1.1.1.12021-04-25T09:00:40.7780969Zsignin2021-04-25T09:00:40.7780969Z[{"Key":"userAgent","Value":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"}]271ac223-695b-418e-85b3-7809070ee33erealtime86a45315157fb75c3a6e0936ef854c139df99bdfbde4bd7e7f1bc685c36389082021-05-23T08:20:41.9161522Zcity: San Jose
state: California
countryOrRegion: US
geoCoordinates: {"latitude": 37.33053, "longitude": -121.8382}
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe2.2.2.22021-04-28T11:40:11.333738Zsignin2021-04-28T11:40:11.333738Z[{"Key":"userAgent","Value":"python-requests/2.18.4"}]6f74b0f4-dabc-49af-aa87-3aaba042babarealtimec0e94938cddbb849ef64dbb6a98189ab3d93cdec4c4f95923ac935a91486def22021-05-23T08:20:29.027631Zcity: Frankfurt Am Main
state: Hessen
countryOrRegion: DE
geoCoordinates: {"latitude": 50.1109, "longitude": 8.6821}
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe3.3.3.32021-04-29T08:03:23.5302796Zsignin2021-04-29T08:03:23.5302796Z[{"Key":"userAgent","Value":"python-requests/2.18.4"}]069f7e67-3692-4191-a84d-14ab0aa1babarealtimec197aea67197503695f6dbddd9af2b3adcd1e8571f8381e96707ac71162d1cdf2021-05-23T08:20:42.1561664Zcity: Paris
state: Paris
countryOrRegion: FR
geoCoordinates: {"latitude": 48.86023, "longitude": 2.34107}
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe5.5.5.52021-05-07T06:00:45.0034244Zsignin2021-05-07T06:00:45.0034244Z[{"Key":"userAgent","Value":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36"}]dec7bb21-5a9b-45ff-84d6-b1538da801bcrealtime8b29fae724e168a32412e2bdc630540588df7558ac647772c36d957656b6e1562021-05-23T08:20:42.2461705Zcity: Tanglin
state: South West
countryOrRegion: SG
geoCoordinates: {"latitude": 1.32, "longitude": 103.8198}
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe4.4.4.42021-05-09T09:41:24.9769131Zsignin2021-05-09T09:41:24.9769131Z[{"Key":"userAgent","Value":"BAV2ROPC"}]f9dbd73b-8e7f-4bcd-93a7-2a7c1d4cbabarealtimedbc1272033adf3a2e960ce438a671de91b4b1b917e250ec575492156eb64f6eb2021-05-23T08:20:29.0726385Zcity: Stockholm
state: Stockholms Lan
countryOrRegion: SE
geoCoordinates: {"latitude": 59.31512, "longitude": 18.05132}
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn Doe1.2.3.42021-05-11T07:15:33.6885155Zsignin2021-05-11T07:15:33.6885155Z[{"Key":"userAgent","Value":"python-requests/2.25.1"}]5bb85e1f-1933-4698-831d-fbeb40aebabarealtime969476f4d6d20717dfaea9f2df92945f9d736240d53b4187b50579003bf2d0112021-05-23T08:20:42.2911741Zcity: Dublin
state: Dublin
countryOrRegion: IE
geoCoordinates: {"latitude": 53.35389, "longitude": -6.24333}


Retrieves the properties of a collection of riskDetection objects.

Required Permissions#


Base Command#



Argument NameDescriptionRequired
updated_timeThe time elapsed since the risky user was last updated, formatted as <number> <time unit>, e.g., 12 hours or 7 days.Optional
risk_levelRisk level of the detected risky user. The possible values are low, medium, high, hidden, none, and unknownFeatureValue.Optional
risk_stateState of the user's risk. The possible values are none, confirmedSafe, remediated, dismissed, atRisk, confirmedCompromised, and unknownFutureValue.Optional
risk_detailDetails of the detected risk. The possible values are none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, adminConfirmedSigninCompromised, hidden, adminConfirmedUserCompromised, and unknownFutureValue.Optional
filter_expressionA custom query in OData syntax. Using this overrides all arguments, except for next_link. For more details, see
limitNumber of results to provide. Default is 50.Optional
next_linkA link that specifies a starting point for subsequent calls. Using this argument overrides all other arguments.Optional
user_nameRisky user principal name.Optional

Context Output#

AADIdentityProtection.RiskyUsers.idstringUnique ID of the risky user.
AADIdentityProtection.RiskyUsers.isDeletedBooleanIndicates whether the user is deleted.
AADIdentityProtection.RiskyUsers.isProcessingBooleanIndicates whether a user's risky state is being processed by the backend.
AADIdentityProtection.RiskyUsers.riskLastUpdatedDateTimeDateTimeThe date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using the ISO 8601 format and is always in UTC time.
AADIdentityProtection.RiskyUsers.riskLevelstringRisk level of the detected risky user. The possible values are low, medium, high, hidden, none, and unknownFutureValue.
AADIdentityProtection.RiskyUsers.riskStatestringState of the user's risk. The possible values are none, confirmedSafe, remediated, dismissed, atRisk, confirmedCompromised, and unknownFutureValue.
AADIdentityProtection.RiskyUsers.riskDetailstringReason why the user is considered a risky user. The possible values are limited to none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, adminConfirmedSigninCompromised, hidden, adminConfirmedUserCompromised, and unknownFutureValue.
AADIdentityProtection.RiskyUsers.userDisplayNamestringRisky user display name.
AADIdentityProtection.RiskyUsers.userPrincipalNamestringRisky user principal name.

Command Example#


Context Example#

"AADIdentityProtection": {
"RiskyUsers": [
"id": "3fa9f28b-eb0e-463a-ba7b-8089fe9991e2",
"isDeleted": false,
"isProcessing": false,
"riskDetail": "none",
"riskLastUpdatedDateTime": "2021-07-21T17:56:28.958147Z",
"riskLevel": "medium",
"riskState": "atRisk",
"userDisplayName": "John Doe",
"userPrincipalName": ""

Human Readable Output#

Risky Users (1 result)#

User Principal NameUser Display NameIDIs DeletedIs ProcessingRisk DetailRisk Last Updated Date TimeRisk LevelRisk State
jdoe@example.comJohn Doe3fa9f28b-eb0e-463a-ba7b-8089fe9991e2falsefalsenone2021-07-21T17:56:28.958147ZmediumatRisk


Gets the risk history of a riskyUser resource.

Required Permissions#

IdentityRiskyUser.Read.All IdentityRiskyUser.ReadWrite.All

Base Command#



Argument NameDescriptionRequired
user_idUnique ID of the user.Required
limitNumber of results to provide. Default is 50.Optional
filter_expressionA custom query in OData syntax. Using this overrides all arguments, except for next_link. For more details, see
next_linkA link that specifies a starting point for subsequent calls. Using this argument overrides all other arguments.Optional

Context Output#

AADIdentityProtection.RiskyUserHistory.idstringUnique ID of the risky user.
AADIdentityProtection.RiskyUserHistory.isDeletedBooleanIndicates whether the user is deleted.
AADIdentityProtection.RiskyUserHistory.isProcessingBooleanIndicates whether a user's risky state is being processed by the backend.
AADIdentityProtection.RiskyUserHistory.riskLastUpdatedDateTimeDateTimeThe date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using the ISO 8601 format and is always in UTC time.
AADIdentityProtection.RiskyUserHistory.riskLevelstringRisk level of the detected risky user. The possible values are low, medium, high, hidden, none, and unknownFutureValue.
AADIdentityProtection.RiskyUserHistory.riskStatestringState of the user's risk. The possible values are none, confirmedSafe, remediated, dismissed, atRisk, confirmedCompromised, and unknownFutureValue.
AADIdentityProtection.RiskyUserHistory.riskDetailstringReason why the user is considered a risky user. The possible values are limited to none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, adminConfirmedSigninCompromised, hidden, adminConfirmedUserCompromised, and unknownFutureValue.
AADIdentityProtection.RiskyUserHistory.userDisplayNamestringRisky user display name.
AADIdentityProtection.RiskyUserHistory.userPrincipalNamestringRisky user principal name.

Command Example#

!azure-ad-identity-protection-risky-user-history-list user_id="3fa9f28b-eb0e-463a-ba7b-8089fe9991e2"

Context Example#

"AADIdentityProtection": {
"RiskyUserHistory": [
"activity": {
"detail": null,
"eventTypes": [
"riskEventTypes": [
"id": "3fa9f28b-eb0e-463a-ba7b-8089fe9991e2637571860258849619",
"initiatedBy": null,
"isDeleted": false,
"isProcessing": false,
"riskDetail": "none",
"riskLastUpdatedDateTime": "2021-05-21T09:27:05.8849619Z",
"riskLevel": "high",
"riskState": "atRisk",
"userDisplayName": "John Doe",
"userId": "3fa9f28b-eb0e-463a-ba7b-8089fe9991e2",
"userPrincipalName": ""

Human Readable Output#

Risky User History For 3Fa9F28B-Eb0E-463A-Ba7B-8089Fe9991E2 (12 results)#

User IDUser Principal NameUser Display NameActivityIDInitiated ByIs DeletedIs ProcessingRisk DetailRisk Last Updated Date TimeRisk LevelRisk State
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures,
riskEventTypes: unfamiliarFeatures,
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes:
detail: userPerformedSecuredPasswordChange
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: mcasImpossibleTravel
riskEventTypes: mcasImpossibleTravel
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: mcasImpossibleTravel
riskEventTypes: mcasImpossibleTravel
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes: unfamiliarFeatures
riskEventTypes: unfamiliarFeatures
detail: null
3fa9f28b-eb0e-463a-ba7b-8089fe9991e2jdoe@example.comJohn DoeeventTypes:
detail: adminDismissedAllRiskForUser


Confirms one or more riskyUser objects as compromised. This action sets the targeted user's risk level to high.

Required Permissions#


Base Command#



Argument NameDescriptionRequired
user_idsOne or more user IDs, comma-separated.Required

Context Output#

There is no context output for this command.

Command Example#

!azure-ad-identity-protection-risky-user-confirm-compromised user_ids="3fa9f28b-eb0e-463a-ba7b-8089fe9991e3"

Human Readable Output#

โœ… Confirmed successfully.


Dismisses the risk of one or more riskyUser objects. This action sets the targeted user's risk level to none.

Required Permissions#


Base Command#



Argument NameDescriptionRequired
user_idsOne or more user IDs, comma-separated.Required

Context Output#

There is no context output for this command.

Command Example#

!azure-ad-identity-protection-risky-user-dismiss user_ids="3fa9f28b-eb0e-463a-ba7b-8089fe9991e2"

Human Readable Output#

โœ… Dismissed successfully.