RiskyUsers
Returns users flagged as risky by identity protection, including risk level, risk state, and processing status.
View-Specific Information
SELECT
SELECT * FROM RiskyUsers
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskyUser.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.
Columns
| Name | Type | Description |
| id [KEY] | String | The unique identifier for the risky user. |
| isDeleted | Bool | Indicates whether the user is deleted. |
| isProcessing | Bool | Indicates whether the risk state of the user is currently being processed. |
| riskDetail | String | The detail providing further information about the risk associated with the user. |
| riskLastUpdatedDateTime | Datetime | The date and time when the risk state of the user was last updated. |
| riskLevel | String | The level of risk associated with the user, such as low, medium, or high. |
| riskState | String | The state of the reported risk for the user, such as atRisk, confirmedSafe, or remediated. |
| userDisplayName | String | The display name of the risky user. |
| userPrincipalName | String | The user principal name of the risky user. |