Tableau Connector for Microsoft Entra ID

Build 26.0.9770

RiskDetections

Returns risk detections identified by identity protection, including detection type, risk level, activity, and location details.

View-Specific Information

SELECT


SELECT * FROM RiskDetections
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskEvent.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.

Columns

Name Type Description
id [KEY] String The unique identifier for the risk detection.
activity String The type of activity associated with the risk detection, such as a sign-in or a user activity.
activityDateTime Datetime The date and time when the activity associated with the risk detection occurred.
additionalInfo String Additional information related to the risk detection.
correlationId String The correlation identifier that links the risk detection to a specific sign-in activity.
detectedDateTime Datetime The date and time when the risk was detected.
detectionTimingType String The timing of the risk detection, indicating whether it was detected in real time or offline.
ipAddress String The IP address of the client from which the risk occurred.
lastUpdatedDateTime Datetime The date and time when the risk detection was last updated.
location_city String The city in which the risk detection occurred.
location_countryOrRegion String The country or region in which the risk detection occurred.
location_geoCoordinates_altitude Double The altitude of the location, in meters, where the risk detection occurred.
location_geoCoordinates_latitude Double The latitude of the location where the risk detection occurred.
location_geoCoordinates_longitude Double The longitude of the location where the risk detection occurred.
location_state String The state or province in which the risk detection occurred.
requestId String The identifier of the request associated with the risk detection.
riskDetail String The detail providing further information about the risk detection.
riskEventType String The type of risk event detected, such as anonymizedIPAddress or unfamiliarFeatures.
riskLevel String The level of risk associated with the detection, such as low, medium, or high.
riskState String The state of the reported risk, such as atRisk, confirmedSafe, or remediated.
source String The source of the risk detection.
tokenIssuerType String The type of token issuer for the detected sign-in risk.
userDisplayName String The display name of the user associated with the risk detection.
userId String The unique identifier of the user associated with the risk detection.
userPrincipalName String The user principal name of the user associated with the risk detection.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770