Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Entra credential and risky-sign-in findings. Ingest Entra Identity Protection risk detections. Location flags supplement provider risk evidence; they do not by themselves prove compromise. Current availability: Implemented; Identity Protection entitlement required. Before you start. Company administrator or TLS owner; a dedicated provider application for this company. A separate test tenant or approved test records and company responders who can verify results. An eligible Entra ID P1/P2 license for the risk-detection data required and IdentityRiskEvent.Read.All application permission with admin consent. Step 1. Create a dedicated Entra application in the customer tenant. Grant IdentityRiskEvent.Read.All application permission and the appropriate administrator consent. Step 2. Open Company > Security > Microsoft Entra ID. Save tenant ID, client ID and secret. Select minimum severity and incident/email routing. Step 3. Optionally enter two-letter country codes from the company's approved travel/access policy. A flagged country is investigation context and does not automatically become critical severity. Step 4. Run Verify read access, then Enable sync. The connector reads Graph identityProtection/riskDetections and follows validated pagination. Step 5. Test a known eligible leaked-credential or risky-sign-in detection. Check provider risk level, user, event type and country evidence against the resulting company ticket. Step 6. Investigate with the customer before remediation. Conditional Access changes, password reset, session revocation and provider remediation are separate authorized operations. Now verify the result. A known provider finding creates exactly one company security event and one linked ticket when its severity qualifies. Repeat the same event and verify there is no duplicate ticket or responder notification. Pause the connection, verify no further polling, and check wrong-company API access is denied. If you get stuck. No detections can mean no risk in the window, insufficient license detail or missing permissions; verify with the tenant administrator. Reported lost/stolen devices can be entered manually in Security; geography alone cannot prove theft. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.