🚨 Heads up for Microsoft Entra Administrators
Starting October 1, 2026, Microsoft will retire the legacy User Risk Policy in Microsoft Entra ID Protection.
At first glance, this may seem like another legacy feature reaching end of life. In reality, it has important security implications.
🛡️ Why it matters The legacy User Risk Policy has long helped protect organizations by automatically requiring users to perform a secure password reset when Microsoft detects their account has likely been compromised.
⚠️ What’s changing? Microsoft is consolidating identity protection policies under Conditional Access.
If you’re still relying on the legacy User Risk Policy and haven’t recreated it as a Conditional Access policy, the protection doesn’t automatically migrate. Once the legacy policy is retired, it will stop enforcing user risk-based remediation, potentially leaving compromised accounts without the expected protection.
✅ What you should do before October 1, 2026 🔍 Check whether you’re still using the legacy User Risk or Sign-in Risk policies.
🔑 Verify you have Microsoft Entra ID P2 licensing.
🔄 Recreate your user risk and sign-in risk policies using Conditional Access.
🚫 If you’re planning to use Conditional Access, ensure Security Defaults are disabled, as the two cannot be used together.
🌐 This change is another step in Microsoft’s continued move toward a unified Zero Trust approach, with Conditional Access serving as the central policy engine for identity and access protection.
Has your organization already completed the migration, or is it still part of your roadmap?
