Legacy Risk Policies in Microsoft Entra ID Protection Are Being Retired. Here Is What Admins Need to Do
Microsoft has confirmed that the legacy User Risk and Sign-in Risk policies in Microsoft Entra ID Protection will be retired on October 1, 2026. If your organization still relies on these built-in policies, this is worth acting on now, not later.
What is changing
For years, Entra ID Protection (formerly Identity Protection) has offered two built-in policies. A User Risk policy and a Sign-in Risk policy. These could automatically respond when a user or sign-in was flagged as risky, for example by forcing a secure password change or blocking access.
Microsoft is retiring these legacy policies. Going forward, risk-based enforcement is handled through Conditional Access instead. This is part of Microsoft’s broader move to consolidate identity protection, Zero Trust, and access control into one policy framework.
Why it matters
If your organization has not migrated by October 1, 2026, the legacy policies stop protecting your users. Anyone flagged as high risk may no longer be prompted to reset their password or complete additional verification, unless an equivalent Conditional Access policy is already in place and enabled.
This is not a cosmetic change. It is a change to how compromised accounts get contained.
What to check now
- Are you still using the legacy User Risk or Sign-in Risk policy in Entra ID Protection.
- Do you have Microsoft Entra ID P2 or Microsoft Entra Suite licensing. Full Identity Protection features require one of these.
- Have you created equivalent User Risk and Sign-in Risk policies in Conditional Access, and tested them in report-only mode before turning them on.
- Are you using Security Defaults. If so, they must be disabled before a Conditional Access policy can be enabled. Both cannot run at the same time.
How the migration works
Microsoft recommends a straightforward path.
- Build equivalent user risk and sign-in risk policies in Conditional Access, starting in report-only mode.
- Review the report-only results to confirm the policy behaves as expected.
- Turn the new Conditional Access policy on.
- Disable the old legacy policy in Entra ID Protection.
Microsoft also recommends not combining sign-in risk and user risk conditions in the same Conditional Access policy. Keep them as separate policies.
If you need help, Microsoft supports migration requests directly through the Entra admin center support channel, under the Identity Protection problem type.
The Steeves recommendation
Treat this as a project with a deadline, not a background task. Review your current Identity Protection setup, confirm your licensing, and build the Conditional Access equivalents in report-only mode well before October 2026. Waiting until the deadline risks a quiet gap in protection, not a clean cutover.
If you manage Microsoft 365 or Intune environments and want a second set of eyes on your Conditional Access and Identity Protection setup, Steeves and Associates can help you plan the migration.
Sources
- Microsoft Learn, Risk policies – Microsoft Entra ID Protection
- Microsoft Learn, Microsoft Entra ID Protection risk-based access policies
- Microsoft Learn, Configure Security Defaults for Microsoft Entra ID
- Microsoft Tech Community, What’s new in Microsoft Entra – June 2025