T
Threats
Microsoft Entra ID Protection Legacy Risk Policy Retirement
Microsoft is retiring its legacy User Risk and Sign-in Risk policies in Microsoft Entra ID Protection on 1 October 2026.
These policies help organisations respond when Microsoft detects signs that a user account or sign-in may be compromised. Microsoft will not automatically convert these legacy policies into Conditional Access policies. Organisations that rely on them must manually recreate equivalent controls in Microsoft Entra Conditional Access before the retirement date.
What Is Changing?
Microsoft currently provides legacy risk policies within Entra ID Protection for two common scenarios:
User risk: The likelihood that a user account has been compromised.
Sign-in risk: The likelihood that a particular authentication attempt was not made by the legitimate user.
Microsoft is moving these controls to Conditional Access, where organisations can create more flexible, risk-based access policies.
If your organisation uses one or both legacy policies, equivalent Conditional Access policies should be configured before the retirement date.
Why This Matters
Risk-based identity controls can help limit account compromise by requiring additional verification or remediation when suspicious activity is detected.
If legacy policies are retired without equivalent Conditional Access controls in place, an organisation may lose the automated responses it currently relies on for risky users or sign-ins. This could create an unintended gap in identity protection.
The change also provides an opportunity to review whether existing controls still reflect your organisation’s users, applications, licensing and risk appetite.
Who May Be Affected?
Your organisation may be affected if its Microsoft Entra tenant has either of the following enabled in Entra ID Protection:
Legacy User Risk policy
Legacy Sign-in Risk policy
Exposure is determined by tenant configuration rather than a particular software version. Organisations that do not use the retiring policies are not directly affected, but may still benefit from reviewing their Conditional Access posture.
Recommended Action
Because the legacy policies will not be converted automatically, organisations using User Risk or Sign-in Risk policies should complete the following migration before 1 October 2026:
Create separate equivalent Conditional Access policies before 1 October 2026.
Validate the new policies in report-only mode before enabling them.
Enable the validated policies, then disable the corresponding legacy policies.
Secure ISS recommends completing the migration before the retirement date to avoid a gap in identity protection.
Reference
Need Help?
Secure ISS can assist with reviewing legacy Microsoft Entra risk policies, designing equivalent Conditional Access controls and validating the migration before the retirement date.
Call 1300 769 460 or contact your Secure ISS representative.

