Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Important: Migrate your User Risk Policy in Microsoft Entra ID Protection before October 1, 2026

Message ID
MC1448337
View in Message Center
Service
Microsoft Entra
Category
Plan for Change
Tag
Admin impact
Rollout
October 2026

Details

[Introduction]

You're receiving this message because your tenant has a legacy User Risk Policy enabled in Microsoft Entra ID Protection. The User Risk Policy will be retired on October 1, 2026, and after that date the legacy policy will be automatically disabled.

To avoid disruption to your tenant's risk-based protections, migrate your policy to Conditional Access before the retirement date.

[When this will happen]

  • October 1, 2026: The legacy User Risk Policy in Microsoft Entra ID Protection will be retired and automatically disabled.

[How this affects your organization]

Who is affected

  • Organizations that have a legacy User Risk Policy enabled in Microsoft Entra ID Protection.

What will happen

  • The User Risk Policy in Microsoft Entra ID Protection will be retired on October 1, 2026.
  • After the retirement date, the legacy User Risk Policy will be automatically disabled.
  • If no equivalent risk-based policy is enabled in Conditional Access, your users will lose the protections previously enforced by the legacy policy.

[What you can do to prepare]

  1. Migrate your User Risk Policy to Conditional Access before October 1, 2026 by following the Migrate risk policies to Conditional Access guide. A Security Administrator or Global Administrator role is required to disable the legacy risk policy.
  2. Review your legacy policy in the Microsoft Entra ID Protection portal, and manage Conditional Access policies in the Microsoft Entra admin center.
  3. If Security Defaults are enabled in your tenant, disable them first, as they must be turned off before you can create Conditional Access policies.
  4. If you need assistance, follow the Help section in the Migrate risk policies to Conditional Access guide or submit a support request: Technical → Microsoft Entra Sign-in and Multifactor Authentication → Identity Protection → Configure risk policies.

Learn more

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.