All posts
Compliance & Baselines 2 min read

Legacy Entra ID risk policies retire october 1: What MSPs Need to Migrate Now

Microsoft is retiring the legacy user risk and sign-in risk policies in Entra ID Protection on October 1, 2026. Here is what MSPs need to check across every tenant before then.

M Michael September 4, 2026
Legacy Entra ID risk policies retire october 1: What MSPs Need to Migrate Now

A hard deadline is landing in every P2 tenant

Microsoft has confirmed that the legacy risk policies configured directly in Entra ID Protection, the classic user risk policy and sign-in risk policy, will be retired on October 1, 2026. After that date they stop enforcing entirely. If a tenant is still relying on these legacy policies instead of their Conditional Access equivalents, high risk users and risky sign ins will quietly stop triggering password resets or step up authentication, with no error and no obvious warning in the portal.

This is the kind of change that is easy to miss across a large book of tenants. The policies have technically been in a read only state for a while, so many admins already assume the migration happened. It has not always happened everywhere.

What actually needs to change

For every tenant with Entra ID P2 or the Entra Suite, the fix is the same:

  • Create equivalent user risk based and sign in risk based policies directly in Conditional Access, starting in report only mode
  • Review the report only results to confirm the new policies catch what the old ones caught
  • Turn the policies on, then disable the legacy risk policy inside ID Protection
  • Avoid combining sign in risk and user risk conditions in a single Conditional Access policy since Microsoft recommends separate policies for each

Microsoft's own guidance is to require risk remediation at high user risk and require multifactor authentication at medium or high sign in risk, paired with sign in frequency set to every time as a session control.

The MSP angle

A single tenant migration is a checklist. Across dozens of tenants it is a drift problem, and it is exactly the kind of gap that a baseline audit is built to catch: is Conditional Access covering user and sign in risk in every environment, or is one tenant still quietly depending on a policy that stops working on October 1.

Worth checking this week: do you know, right now, which of your tenants still have the legacy risk policy enabled instead of its Conditional Access replacement?

One baseline. Every tenant. Zero subscriptions.

Self-hosted, source included, buy it once. Try the full demo offline before you pay a cent.

See pricing