Microsoft is continuing to evolveย Require risk remediation in Conditional Accessโmoving away from a one-size-fits-all response toward remediation that adapts to the type of identity threat detected.
๐ก๏ธ What is Adaptive Risk Remediation?
Instead of always responding to user risk with the same action, Microsoft Entra ID Protection can determine the appropriate remediation based on the risk scenario and authentication method.
For example:
๐ Compromised password
โ Require a secure password change
โ Revoke previous sessions
๐ Passwordless user / non-password compromise
โ Revoke active sessions
โ Require reauthentication
This means organizations can use a single Require risk remediation control while Microsoft Entra determines the appropriate response.
๐จ Why this matters
Traditional user-risk policies often relied on:
High User Risk โ Require Password Change
But that approach doesn't work equally well in a world where organizations are increasingly adopting passkeys, Windows Hello for Business, FIDO2 security keys, and other passwordless authentication methods.
Require risk remediation supports both password-based and passwordless users, allowing the response to adapt to the detected threat.
๐ Another reason to review your policies now
Microsoft is retiring the legacy User Risk and Sign-in Risk policies in Entra ID Protection on:
๐ October 1, 2026
Organizations still using these legacy policies should migrate them to Conditional Access.
If you're migrating a traditional user-risk policy, this is also a good opportunity to evaluate Require risk remediation rather than simply recreating the old Require password change behavior.
โ ๏ธ User Risk โ Sign-in Risk
This distinction remains important.
Require risk remediation addresses USER RISKโthe probability that the identity itself has been compromised.
SIGN-IN RISK evaluates whether a particular authentication attempt might be unauthorized and should be handled through a separate Conditional Access policy. Microsoft recommends requiring MFA for medium- or high-risk sign-ins.
A modern approach could therefore look like:
๐ค High User Risk
โ Require Risk Remediation
๐จ Medium/High Sign-in Risk
โ Require Strong Authentication / MFA
๐ก Bottom line
Identity protection is moving beyond simply asking:
โIs this user risky?โ
The more important question is becoming:
โWhy is this user risky, and what is the appropriate remediation for that specific threat?โ
Adaptive Risk Remediation is an important step toward making identity security more context-aware, automated, and compatible with both password and passwordless authentication.
Read More: