Excel Add-In for Microsoft Entra ID

Build 26.0.9770

RiskyUsers

Returns users flagged as risky by identity protection, including risk level, risk state, and processing status.

View-Specific Information

SELECT


SELECT * FROM RiskyUsers
Note: Querying this view requires additional scopes than the default. In order to access this view, you must have the IdentityRiskyUser.Read.All permission and the signed-in user must be assigned a supported Microsoft Entra ID role or a custom role with a supported role permission of Global Reader, Security Operator, Security Reader, or Security Administrator.

Columns

Name Type Description
id [KEY] String The unique identifier for the risky user.
isDeleted Bool Indicates whether the user is deleted.
isProcessing Bool Indicates whether the risk state of the user is currently being processed.
riskDetail String The detail providing further information about the risk associated with the user.
riskLastUpdatedDateTime Datetime The date and time when the risk state of the user was last updated.
riskLevel String The level of risk associated with the user, such as low, medium, or high.
riskState String The state of the reported risk for the user, such as atRisk, confirmedSafe, or remediated.
userDisplayName String The display name of the risky user.
userPrincipalName String The user principal name of the risky user.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770