Microsoft Entra ID Protection Risk Policies Are Retiring. Don’t Leave Conditional Access Until the Last Minute.

If you've spent time managing Microsoft 365 security, there's a good chance you've come across the User risk and Sign-in risk policies within Microsoft Entra ID Protection.
They've quietly helped organisations respond to compromised accounts and suspicious sign-ins for years. Because they're often configured once and left alone, they're also the type of security control that's easy to forget about.
That's why Microsoft's recent announcement is an important one.
From 1 October 2026, Microsoft will retire the legacy User risk and Sign-in risk policy experience in Microsoft Entra ID Protection. Organisations still using these policies will need to move them to Conditional Access before the deadline.
Importantly, Microsoft Entra ID Protection itself is not being retired. The risk detection capabilities remain. What's changing is where organisations manage and enforce their responses to those risks.
Why is Microsoft making this change?
The answer is fairly straightforward.
Conditional Access has become Microsoft's central platform for access control decisions. It already allows organisations to enforce policies based on factors such as:
• User location
• Device compliance
• Authentication strength
• Applications being accessed
• User groups and roles
Risk signals from Entra ID Protection, including User risk and Sign-in risk, can also be used within Conditional Access.
Rather than managing risk response through a separate set of legacy policies, Microsoft wants organisations to manage everything within a single Conditional Access framework.
For administrators, that means simpler management, improved reporting and greater flexibility.
Why should organisations act now?
Identity projects are rarely the kind of work you want to leave until the last minute.
Many organisations have been using the same risk policies for several years. Requirements may have changed, exclusions might no longer be appropriate and documentation is often incomplete.
The migration itself is usually straightforward.
The risk comes from discovering too late that critical security controls rely on a legacy configuration that nobody has reviewed for years.
Identity controls protect access to email, files, applications and sensitive data. They deserve a little more attention than a rushed migration project.
What needs to change?
If you're currently using the legacy User risk or Sign-in risk policies, Microsoft recommends recreating them within Conditional Access.
For User risk, organisations should typically require risk remediation when a user's risk level is high.
For Sign-in risk, Microsoft recommends requiring multifactor authentication for medium and high-risk sign-ins.
One important recommendation is to keep User risk and Sign-in risk as separate Conditional Access policies rather than combining them.
It may seem like a small detail, but separate policies are easier to troubleshoot, manage and report on over time.
Don't just copy the old settings
This retirement creates a valuable opportunity to review whether your current approach still makes sense.
Before migrating, it's worth checking:
• Which users are covered by existing policies
• Which risk levels trigger action
• Whether accounts are challenged, blocked or remediated
• Whether emergency access accounts are excluded
• Whether service accounts require separate treatment
• Whether users are registered for MFA
• Whether password writeback is configured if secure password changes are required
A policy that made perfect sense five years ago may not be the best fit today.
Use Report-Only Mode
The good news is that there's no need to make changes and hope for the best.
Conditional Access includes Report-Only Mode, allowing organisations to test policies before enforcement.
This provides an opportunity to:
• Validate settings
• Review impacted users
• Check exclusions• Identify unexpected behaviour
• Reduce the risk of user disruption
For schools, charities and other organisations with limited IT resources, this can make the transition significantly smoother.
What we recommend
A sensible approach would be:
1. Audit existing User risk and Sign-in risk policies.
2. Design equivalent Conditional Access policies.
3. Enable Report-Only Mode and review the results.
4. Pilot with a small group where possible.
5. Move to enforcement once validated.
6. Disable the legacy policies and continue monitoring.
Final thoughts
This isn't the biggest Microsoft 365 change you'll see this year, but it's an important one.
Identity has become the primary security perimeter for most organisations and risk-based access controls play a key role in protecting it.
The good news is that Microsoft has provided plenty of notice and a clear migration path. The challenge is simply making sure it doesn't stay on the "we'll look at that later" list for too long.
If your organisation is still using the legacy Microsoft Entra ID Protection User risk or Sign-in risk policies, now is the time to start planning the move to Conditional Access.
It should be relatively straightforward housekeeping. But when that housekeeping helps protect the front door to your environment, it's worth getting right.
If you're unsure whether your organisation is currently using these legacy policies, Smartdesc can help review your Entra configuration, assess your Conditional Access policies and support a smooth migration ahead of the October 2026 deadline. Reach out here.