[Introduction]
You're receiving this message because your tenant has a legacy User Risk Policy enabled in Microsoft Entra ID Protection. The User Risk Policy will be retired on October 1, 2026, and after that date the legacy policy will be automatically disabled.
To avoid disruption to your tenant's risk-based protections, migrate your policy to Conditional Access before the retirement date.
[When this will happen]
- October 1, 2026: The legacy User Risk Policy in Microsoft Entra ID Protection will be retired and automatically disabled.
[How this affects your organization]
Who is affected
- Organizations that have a legacy User Risk Policy enabled in Microsoft Entra ID Protection.
What will happen
- The User Risk Policy in Microsoft Entra ID Protection will be retired on October 1, 2026.
- After the retirement date, the legacy User Risk Policy will be automatically disabled.
- If no equivalent risk-based policy is enabled in Conditional Access, your users will lose the protections previously enforced by the legacy policy.
[What you can do to prepare]
- Migrate your User Risk Policy to Conditional Access before October 1, 2026 by following the Migrate risk policies to Conditional Access guide. A Security Administrator or Global Administrator role is required to disable the legacy risk policy.
- Review your legacy policy in the Microsoft Entra ID Protection portal, and manage Conditional Access policies in the Microsoft Entra admin center.
- If Security Defaults are enabled in your tenant, disable them first, as they must be turned off before you can create Conditional Access policies.
- If you need assistance, follow the Help section in the Migrate risk policies to Conditional Access guide or submit a support request: Technical → Microsoft Entra Sign-in and Multifactor Authentication → Identity Protection → Configure risk policies.
Learn more
- What's new in Microsoft Entra
- Migrate risk policies to Conditional Access
- Required roles for ID Protection
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.