entra-id-protection

Installation
SKILL.md

Microsoft Entra ID Protection

Microsoft Entra ID Protection uses Microsoft's threat intelligence and ML to detect identity risk (user risk and sign-in risk), automate remediation, and surface a queue of risky users and sign-ins for investigation. Requires Entra ID P2 to enable risk policies.

When to use

Adding risk-based, adaptive protection on top of Entra ID and Conditional Access. Use this skill to choose risk thresholds, decide between self-remediation and SOC investigation, and stream signals to Sentinel.

Do not use this skill for on-prem AD attack detection (defender-for-identity), authoring plain CA policies (conditional-access-mfa), or PIM activation (azure-pim).

Map the risk signal to the response

Installs
76
GitHub Stars
173
First Seen
Jun 10, 2026
entra-id-protection — vinayaklatthe/microsoft-security-skills