entra-id-protection
Installation
SKILL.md
Microsoft Entra ID Protection
Microsoft Entra ID Protection uses Microsoft's threat intelligence and ML to detect identity risk (user risk and sign-in risk), automate remediation, and surface a queue of risky users and sign-ins for investigation. Requires Entra ID P2 to enable risk policies.
When to use
Adding risk-based, adaptive protection on top of Entra ID and Conditional Access. Use this skill to choose risk thresholds, decide between self-remediation and SOC investigation, and stream signals to Sentinel.
Do not use this skill for on-prem AD attack detection (defender-for-identity), authoring
plain CA policies (conditional-access-mfa), or PIM activation (azure-pim).