‹ Back to list
Plan for ChangeMC1448340

Important: Migrate your Sign-in Risk Policy in Microsoft Entra ID Protection before October 1, 2026

Services: Microsoft Entra· Published: 2026-08-05· MS modified: 2026-08-05
Admin impact

Microsoft announcement

[Introduction]

You're receiving this message because your tenant has a legacy Sign-in Risk Policy enabled in Microsoft Entra ID Protection. The Sign-in Risk Policy will be retired on October 1, 2026, and after that date the legacy policy will be automatically disabled.

To avoid disruption to your tenant's risk-based protections, migrate your policy to Conditional Access before the retirement date.

[When this will happen]

  • October 1, 2026: The legacy Sign-in Risk Policy in Microsoft Entra ID Protection will be retired and automatically disabled.

[How this affects your organization]

Who is affected

  • Organizations that have a legacy Sign-in Risk Policy enabled in Microsoft Entra ID Protection.

What will happen

  • The Sign-in Risk Policy in Microsoft Entra ID Protection will be retired on October 1, 2026.
  • After the retirement date, the legacy Sign-in Risk Policy will be automatically disabled.
  • If no equivalent risk-based policy is enabled in Conditional Access, your users will lose the protections previously enforced by the legacy policy.

[What you can do to prepare]

  1. Migrate your Sign-in Risk Policy to Conditional Access before October 1, 2026 by following the Migrate risk policies to Conditional Access guide. A Security Administrator or Global Administrator role is required to disable the legacy risk policy.
  2. Review your legacy policy in the Microsoft Entra ID Protection portal, and manage Conditional Access policies in the Microsoft Entra admin center.
  3. If Security Defaults are enabled in your tenant, disable them first, as they must be turned off before you can create Conditional Access policies.
  4. If you need assistance, follow the Help section in the Migrate risk policies to Conditional Access guide or submit a support request: Technical → Microsoft Entra Sign-in and Multifactor Authentication → Identity Protection → Configure risk policies.

Learn more

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change history