RiskyUserHistory
Returns the risk history of risky users, including the changes to risk level, risk state, and the activity that initiated each change.
View-Specific Information
SELECT
You can filter results by RiskyUserId.- RiskyUserId supports the =, IN operators.
For example, the following queries are processed server-side:
SELECT * FROM RiskyUserHistory WHERE RiskyUserId = 'ffacf701-6caf-4228-9e3b-7e57c14122ee'
SELECT * FROM RiskyUserHistory WHERE RiskyUserId IN (SELECT Id FROM RiskyUsers)
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskyUser.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.
Columns
| Name | Type | Description |
| RiskyUserId | String | The unique identifier of the risky user whose history is being retrieved. |
| id [KEY] | String | The unique identifier for the risky user history entry. |
| isDeleted | String | Indicates whether the user is deleted. |
| isProcessing | String | Indicates whether the risk state of the user is currently being processed. |
| riskDetail | String | The detail providing further information about the risk associated with the user. |
| riskLastUpdatedDateTime | String | The date and time when the risk state of the user was last updated. |
| riskLevel | String | The level of risk associated with the user, such as low, medium, or high. |
| riskState | String | The state of the reported risk for the user, such as atRisk, confirmedSafe, or remediated. |
| userDisplayName | String | The display name of the user associated with the history entry. |
| userPrincipalName | String | The user principal name of the user associated with the history entry. |
| activity_detail | String | The detail providing further information about the activity that triggered the history entry. |
| activity_riskEventTypes | String | The types of risk events associated with the activity that triggered the history entry. |
| initiatedBy | String | Identifies the user or process that initiated the change recorded in the history entry. |
| userId | String | The unique identifier of the user associated with the history entry. |