Microsoft Entra ID Protection uses machine learning across billions of sign-in events to assign a risk level — low, medium, or high — to each authentication attempt. High-risk sign-ins are those that exhibit strong signals of compromise: impossible travel, sign-in from anonymous IPs, malware-linked IP addresses, unfamiliar sign-in properties, or credentials leaked in third-party data breaches.
A Conditional Access policy that blocks high-risk sign-ins acts as an automatic response to these signals, preventing access before an analyst has to review the event. Without this policy, a high-risk sign-in event is recorded in the logs but nothing stops the attacker from accessing the account. With it, the sign-in is blocked at the door and the user is prompted to take a secure recovery action.
This is one of the most impactful Conditional Access policies available — it turns Microsoft's threat intelligence into an automated enforcement action rather than a passive alert.
For most organisations, blocking high-risk sign-ins should apply universally. Some nuances:
After enforcing this control, review these related areas: