To manually resolve risk events, select a risk event or flagged user, then a specific flagged sign-in. Once the pane opens with details of the event, you have the following options for actions to take:
- Resolve: You took action outside of Identity Protection to resolve/close the risk.
- Mark as false positive: Closes the event and improves machine learning by reporting an incorrect risk event.
- Ignore: You have not taken action, but don't want the event on your list.
- Reactivate: Make a resolved, false positive, or ignored risk event active again.
The following screenshot shows details of a risk event that has been closed, showing its resolution was a changed password: