A user is flagged as risky. What does that mean?
Risky is Microsoft's verdict, not Avvi's. It means Microsoft saw something it considers a sign of compromise, and it is a prompt to look rather than a finding.
A risky flag comes from Microsoft rather than from Avvi. Microsoft’s identity protection watches sign-in behaviour and marks an account when it sees something it associates with compromise.
Avvi reports that flag alongside its level and its state. It does not add a judgement of its own.
Treat a flag as a reason to look, not as a finding. Plenty of flags turn out to be a person on holiday with an unfamiliar network.
How it works
Microsoft assigns each flagged account a level and a state, and Avvi reports whatever Microsoft set rather than grading it again.
Avvi lists the accounts currently at risk or confirmed compromised, with the level and when it last changed. The list is capped at a hundred accounts.
The signals behind the flag are Microsoft’s, and the useful next step is evidence rather than the label. A sign-in history with times and addresses says more than a level.
Where a client tenant does not have Microsoft Entra ID Premium, none of this is available. Avvi says so plainly rather than reporting no risk, because those are very different answers.
Good to know
No flag is not the same as no risk on a tenant without the right licensing. The check could not run.
A high level is a prompt to check sign-ins, mailbox rules and forwarding for that person, which is what a security investigation does in one request.
What to do next
Ask Avvi for a security investigation on the flagged person. That gathers the sign-in evidence, mailbox rules and forwarding in one go.
Ask for everybody currently flagged across the client if you want the wider picture. That is a separate request and does not need a named person.
If the flag looks genuine, resetting the password and the multi-factor methods signs the person out everywhere, which is the usual first containment step.
If it turns out to be a false positive, ask Avvi to dismiss the flag so it stops appearing in the list.
FAQ
Q: Does Avvi decide who is risky?
A: No. The flag is Microsoft’s, and Avvi reports it.
Q: Can Avvi clear the flag?
A: Yes. Once you have investigated and concluded it is a false positive, ask Avvi to dismiss it. Dismissing is a change, so it is confirmed with you first and recorded.
Q: We see no risky users. Are we clear?
A: Only if the client has the licensing for the check. Without it, no result means unknown.
Q: Is a low level safe to ignore?
A: It is lower priority, not nothing. Check it alongside anything else the client has reported.
Related pages
Check whether sign-ins look suspicious is how to look behind Microsoft’s verdict at the sign-ins it came from.