Microsoft is continuing to evolveย Require risk remediation in Conditional Accessโ€”moving away from a one-size-fits-all response toward remediation that adapts to the type of identity threat detected.

๐Ÿ›ก๏ธ What is Adaptive Risk Remediation?

Instead of always responding to user risk with the same action, Microsoft Entra ID Protection can determine the appropriate remediation based on the risk scenario and authentication method.

For example:

๐Ÿ”‘ Compromised password
โ†’ Require a secure password change
โ†’ Revoke previous sessions

๐Ÿ” Passwordless user / non-password compromise
โ†’ Revoke active sessions
โ†’ Require reauthentication

This means organizations can use a single Require risk remediation control while Microsoft Entra determines the appropriate response.

๐Ÿšจ Why this matters

Traditional user-risk policies often relied on:

High User Risk โ†’ Require Password Change

But that approach doesn't work equally well in a world where organizations are increasingly adopting passkeys, Windows Hello for Business, FIDO2 security keys, and other passwordless authentication methods.

Require risk remediation supports both password-based and passwordless users, allowing the response to adapt to the detected threat.

๐Ÿ“… Another reason to review your policies now

Microsoft is retiring the legacy User Risk and Sign-in Risk policies in Entra ID Protection on:

๐Ÿ“… October 1, 2026

Organizations still using these legacy policies should migrate them to Conditional Access.

If you're migrating a traditional user-risk policy, this is also a good opportunity to evaluate Require risk remediation rather than simply recreating the old Require password change behavior.

โš ๏ธ User Risk โ‰  Sign-in Risk

This distinction remains important.

Require risk remediation addresses USER RISKโ€”the probability that the identity itself has been compromised.

SIGN-IN RISK evaluates whether a particular authentication attempt might be unauthorized and should be handled through a separate Conditional Access policy. Microsoft recommends requiring MFA for medium- or high-risk sign-ins.

A modern approach could therefore look like:

๐Ÿ‘ค High User Risk
โ†’ Require Risk Remediation

๐Ÿšจ Medium/High Sign-in Risk
โ†’ Require Strong Authentication / MFA

๐Ÿ’ก Bottom line

Identity protection is moving beyond simply asking:

โ€œIs this user risky?โ€

The more important question is becoming:

โ€œWhy is this user risky, and what is the appropriate remediation for that specific threat?โ€

Adaptive Risk Remediation is an important step toward making identity security more context-aware, automated, and compatible with both password and passwordless authentication.

Read More:

https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-policies#require-risk-remediation-controlย