What will happen when one of the user's signs in from an anonymous IP address
Your organization has a Microsoft 365 environment. Your current domain it gitbit.org. The Microsoft 365 environment has the current users, groups, and MFA status:
You create a Microsoft Entra Identity Protection sign-in risk policy.
You've assigned the policy to GroupA. You've excluded GroupB from the new policy.
The new policy is configured with the following:
- Sign-in risk condition: low and above
- Access control: Allow but require MFA
Your boss asks you to explain how the policy will affect the users in the table above.
If User1 or User2 signs in from an anonymous IP address, what will happen?