MC807451 - Microsoft Purview | Microsoft Entra: Insider Risk condition in Conditional Access is GA

Service

Microsoft Entra

Published

Jul 1, 2024

Tag

New feature
Admin impact

Platforms

Web

Summary

Microsoft Entra's Insider Risk condition in Conditional Access is now generally available. Organizations with an Entra ID P2 license can set up Conditional Access policies using insider risk signals from Adaptive Protection to enforce actions based on user risk levels. The rollout begins in early July 2024 and completes by early August 2024. Organizations must enable Adaptive Protection and obtain an Entra ID P2 license to use this feature.

More information

As communicated in MC802699 Microsoft Purview | Insider Risk Management: Adaptive Protection + Conditional Access will be GA (June 17, 2024), Microsoft Entra ID Conditional Access integrated with Adaptive Protection—a powerful capability in Microsoft Purview—is coming soon to General Availability. The integration will allow organizations to set up Conditional Access policies that will utilize insider risk signals from Adaptive Protection to enforce actions, like blocks, on users with insider risk levels. For example, a Conditional Access policy with the Insider Risk condition can block elevated risk users from all Microsoft 365 applications while allowing minor risk users to continue to access company resources.

Organizations will need an Entra ID P2 license to use Conditional Access policies integrated with Adaptive Protection. 

This message is associated with Microsoft 365 Roadmap ID 388737.

When this will happen:

General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out early July 2024 and expect to complete by early August 2024.

How this will affect your organization:

Before the rollout: The Insider Risk condition was not available to the organizations who have P2 license.

After this rollout, if you have an Entra ID P2 license, your organization will have access to Conditional Access policies integrated with Adaptive Protection. If you configured the default Insider Risk Conditional Access Policy during public preview, your policy would remain unchanged.

admin settings

What you need to do to prepare:

Your organization will need to enable Adaptive Protection in Insider Risk Management and follow the setup instructions. If you do not already have an Entra ID P2 license, your organization will need to obtain one.

This feature is on by default and accessible to all users with appropriate permissions.

Learn more