Microsoft Entra ID Protection for Canadian SMBs: The Real-Time Identity Risk Engine You Need Before October 2026
Most Canadian SMBs that deployed multi-factor authentication in 2022 checked MFA off the security checklist and moved on. That assumption is now a liability. The Canadian Centre for Cyber Security (CCCS) detected more than 100 adversary-in-the-middle (AiTM) phishing campaigns targeting Canadian Microsoft Entra tenants between 2023 and early 2025. These campaigns do not steal passwords — they steal the authenticated session tokens that MFA produces, bypassing the protection entirely.
The technical countermeasure is Microsoft Entra ID Protection, a machine-learning-driven identity risk engine built into Microsoft 365 and Azure. This post explains what it does, what it detects, and the concrete steps Canadian SMBs need to take — including a looming October 2026 deadline that most organizations are unprepared for.
Why MFA Alone Is No Longer Sufficient
MFA was never designed to stop session token theft. In a standard AiTM attack, the threat actor operates a reverse proxy between the target and the legitimate Microsoft sign-in page. The user completes MFA successfully — the attacker's proxy captures the resulting authenticated session cookie. The attacker replays that cookie in a separate browser session. MFA has been satisfied; the attacker is in.
The scale of the problem is significant. Microsoft's 2025 Digital Defense Report reports that identity-based attacks rose 32 percent in the first half of 2025, with more than 97 percent being password-based attacks executed at massive scale. Microsoft analyzes 38 million identity risk detections per day across its global tenant base.
For Canadian organizations specifically, the CIRA 2025 Cybersecurity Survey found that 42 percent of organizations reported a breach of customer or employee data — up from 29 percent in 2022. And when identities are the entry point, breach costs climb: IBM's 2025 Cost of a Data Breach Report puts the average Canadian breach cost at CA$6.98 million, with phishing-as-initial-vector breaches averaging CA$7.91 million — a 24 percent increase from 2024.
The 2026 Verizon Data Breach Investigations Report reinforces the credential picture: 73 percent of ransomware victims had an associated infostealer infection or credential leak event in the year prior to their attack, and 4 in 10 corporate users have reused an exposed password. The attack surface that Entra ID Protection is designed to monitor is enormous.
What Is Microsoft Entra ID Protection?
Microsoft Entra ID Protection is the identity risk intelligence layer built into Microsoft Entra ID (formerly Azure Active Directory). It continuously analyzes authentication signals across Microsoft's global cloud — billions of sign-ins per day — and uses machine learning to surface anomalous patterns indicating that a user account may be compromised or under active attack.
ID Protection operates at two levels:
Sign-in risk — assessed in real time at the moment of authentication. When a sign-in exhibits unusual characteristics, ID Protection assigns a risk level of Low, Medium, or High and either logs it or enforces a Conditional Access policy response immediately.
User risk — a cumulative assessment of an account's overall exposure. If multiple risky sign-ins are detected, or leaked credentials appear in criminal underground sources, the user risk level rises. A high user risk means the account is likely compromised and requires remediation regardless of how the next sign-in looks.
What Entra ID Protection Detects
The detection library covers a range of real-world attack patterns:
- Anonymous IP address — sign-ins from Tor nodes, known VPN exit points, or IP addresses associated with anonymous infrastructure
- Impossible travel — a user signing in from Toronto and 40 minutes later from a European IP that is geographically implausible for legitimate travel
- Password spray — coordinated low-and-slow attacks testing common passwords across many accounts, designed to avoid triggering lockouts
- Anomalous token — token characteristics inconsistent with the user's baseline, often indicating AiTM session token theft or token replay by an attacker
- Possible attempt to access Primary Refresh Token (PRT) — signals of attacks targeting the long-lived device credential that grants broad access across Microsoft services
- Threat intelligence-based detections — sign-ins from IPs or actors Microsoft's threat intelligence team has identified as actively targeting Microsoft Entra tenants
- Leaked credentials — ID Protection scans dark web sources, criminal forums, and public data breach dumps, then cross-references discovered credentials against your tenant in near-real time
The April 2026 update to Entra ID Protection's detection library added expanded coverage for MFA-related phishing, token abuse, and suspicious inbox activity — directly targeting the AiTM attack patterns the CCCS documented in ITSM.30.031.
Risk-Based Conditional Access: Adaptive Access That Scales to the Threat
Detecting risk signals is only useful if something happens as a result. That is where risk-based Conditional Access policies come in. Rather than applying the same authentication challenge to every sign-in, these policies scale the response to the assessed threat level:
| Risk Level | Typical Policy Response |
|---|---|
| Low | Allow access, log the event |
| Medium | Require MFA re-authentication |
| High (sign-in) | Block access or require phishing-resistant MFA |
| High (user risk) | Require a secure password change before access is restored |
The practical effect: a legitimate employee signing in from their usual device and location sees no friction. An attacker replaying a stolen session token from an anonymizing proxy gets blocked immediately — the policy triggers a new authentication challenge they cannot satisfy.
This adaptive enforcement layer addresses the specific gap that AiTM attacks exploit.
The October 2026 Deadline: What Canadian SMBs Must Do Now
This is the item that requires immediate attention: Microsoft is retiring its legacy Entra ID Protection risk policies on October 1, 2026. The legacy "User risk policy" and "Sign-in risk policy" within the Entra ID Protection dashboard have been read-only since July 2025. On October 1, 2026, they stop enforcing entirely.
Organizations that configured risk policies in Entra ID Protection prior to July 2025 and have not migrated them to Conditional Access will lose their risk-based enforcement at that date — silently. No warning banner at sign-in, no replacement policy created automatically. The protection disappears.
The migration is straightforward but must be done deliberately:
Step 1 — Create equivalent Conditional Access policies. In the Entra admin center (entra.microsoft.com), navigate to Protection → Conditional Access and create new policies that target the Sign-in risk level and User risk level conditions. Mirror the logic of your existing legacy policies — same risk thresholds, same access controls.
Step 2 — Deploy in Report-Only mode first. Report-only mode shows exactly which sign-ins would have been affected, without blocking any access. Review the report for at least two weeks to confirm the policies behave as expected before enforcement.
Step 3 — Switch to On and disable the legacy policies. Flip the new Conditional Access policies from Report-only to On. Then return to the Entra ID Protection blade (Protection → Identity Protection) and disable the legacy User risk policy and Sign-in risk policy. Verify both are showing as disabled.
Step 4 — Confirm enforcement. Review the sign-in logs under Users → Risky sign-ins and check for Conditional Access policy hits. Confirm that high-risk sign-ins are being blocked or challenged as expected in the new framework.
Organizations that have never configured risk policies at all should use this deadline as the forcing function to configure them for the first time.
Licensing Path for Canadian SMBs
Entra ID Protection's risk-based Conditional Access capabilities require Microsoft Entra ID P2 — not P1, which is what Microsoft 365 Business Premium includes by default. Standard Conditional Access (included in Business Premium via P1) supports conditions like location, device compliance, and app targeting, but does not support sign-in risk or user risk as Conditional Access conditions.
For Canadian SMBs that need to add P2 capabilities, the options are:
| Option | What is included | Notes |
|---|---|---|
| Entra ID P2 (standalone) | ID Protection, Privileged Identity Management, Access Reviews | ~CA$13/user/month; apply selectively to high-risk roles |
| Defender Suite for Business Premium add-on | Entra ID P2 + Defender for Endpoint P2 + Defender for Identity + Defender for Cloud Apps | Add-on to existing Business Premium; announced late 2025 |
The selective licensing approach — applying P2 only to administrator accounts and privileged roles rather than every user — is a cost-effective starting point for budget-constrained SMBs. Administrator accounts are the primary target for identity attacks, and a compromised global admin has a vastly larger blast radius than a compromised junior employee account.
At a minimum, ensure that every user holding Microsoft 365 admin, Entra Global Admin, Entra Security Admin, or Exchange Admin roles has P2 licensing and is covered by risk-based Conditional Access policies.
Investigating Risky Accounts: What to Do When Alerts Fire
When Entra ID Protection flags a risky user or sign-in, the right response depends on the risk level and the context:
Medium-risk sign-in, familiar geography — review the sign-in details in the Entra admin portal under Protection → Risky sign-ins. If the sign-in looks legitimate (known device, normal time, expected location), you can dismiss the risk and document the reason. If the details are suspicious, mark it as confirmed compromise and begin remediation.
High-risk sign-in or confirmed token anomaly — treat this as an active security incident. Revoke the user's refresh tokens immediately (Users → select user → Revoke sessions), require a password reset, and audit the account for: mail forwarding rules set to external addresses, OAuth application grants recently added, and SharePoint or OneDrive access logs for data access outside normal patterns. Attackers frequently set persistent forwarding rules immediately after gaining access, so access continues even after the session is revoked.
High user risk from leaked credentials — initiate a forced password reset and re-enroll MFA. The CCCS advisory AL26-010 on SaaS environment compromise recommends reviewing all connected OAuth application grants as a mandatory step in any identity incident, since compromised accounts are routinely used to grant attacker-controlled applications persistent access that survives password resets.
How Entra ID Protection and Phishing-Resistant MFA Work Together
Entra ID Protection and phishing-resistant MFA (FIDO2 security keys, passkeys, certificate-based authentication) are complementary layers — not alternatives. Phishing-resistant MFA prevents session token theft at the source by cryptographically binding authentication to the device and the legitimate origin URL, making AiTM-captured session cookies non-replayable. Entra ID Protection catches what still reaches your environment despite other controls: leaked credentials on the dark web, sign-ins from compromised devices, insider threats, and novel attack patterns.
The CCCS ITSM.30.031 guidance recommends deploying phishing-resistant MFA as the frontline defense and risk-based Conditional Access as the adaptive enforcement layer behind it. Organizations that have deployed phishing-resistant MFA but not risk-based policies are operating with one protective layer where two are needed.
For Canadian SMBs operating under PIPEDA — or preparing for the Consumer Privacy Protection Act (CPPA, formerly Bill C-27) — the ability to demonstrate that access to personal information is governed by adaptive, risk-responsive policies will increasingly be part of your documented privacy accountability framework. Risk-based Conditional Access generates detailed audit logs of every access challenge and decision, which directly supports breach investigation and regulatory reporting obligations.
Sources
- Canadian Centre for Cyber Security. *Defending against adversary-in-the-middle threats with phishing-resistant MFA (ITSM.30.031).* cyber.gc.ca
- Canadian Centre for Cyber Security. *AL26-010: Cyber Criminals Social-Engineering-Enabled Compromise of Enterprise SaaS Environments.* cyber.gc.ca
- Microsoft. *2025 Digital Defense Report.* microsoft.com
- IBM. *Cost of a Data Breach Report 2025 — Canada.* canada.newsroom.ibm.com
- CIRA. *2025 Cybersecurity Survey.* cira.ca
- Verizon. *2026 Data Breach Investigations Report.* verizon.com
- Microsoft. *Entra ID Protection risk-based access policies.* learn.microsoft.com
- Microsoft. *Risk detection types and levels — Entra ID Protection.* learn.microsoft.com
- Microsoft. *Microsoft Entra Plans and Pricing.* microsoft.com
- Microsoft. *Introducing new security and compliance add-ons for Microsoft 365 Business Premium.* techcommunity.microsoft.com
Cloud Forces designs, deploys, and manages Microsoft Entra ID Protection and risk-based Conditional Access policies for Canadian SMBs — including P2 licensing assessment, October 2026 migration support, and incident response procedures when risky accounts are flagged. Explore our Cybersecurity services or contact us to book a complimentary identity risk assessment.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation