Identity & Access Management

ITDR

Identify suspicious identity activity from Microsoft Entra sign-in and audit logs: impossible travel, legacy authentication, and credential attacks.

START FOR FREEREQUEST DEMO
Identity Risk EventsLast 12h
Events
9
Critical
2
Accounts
6
Impossible travel
admin@contoso.com · London → Lagos, 18 min
Critical
Password spray detected
14 accounts targeted in 6 minutes
High
Suspicious agent sign-in
ops-agent identity · new location
Medium
IAM Risk Detection

Surface unused admin permissions and identities without MFA.

Behavioral Detection

Catch impossible travel, legacy auth, and bulk directory changes.

Entra-Native Signals

Detected from Entra ID sign-in and audit logs you already have.

BriteAI-Guided Response

Plain-language root cause and remediation for every risk event.

IAM Risk Detection — Identity View
alice@contoso.com
User · Global Administrator, Owner · No MFA
High
prod-pipeline-sp
Service Principal · Contributor, Key Vault Admin
High
aks-kubelet-mi
Managed Identity · User Access Administrator
Medium
Platform-Engineering
Group · Security Administrator
Medium
bob@contoso.com
User · Contributor
Low
B

BriteAI: “prod-pipeline-sp has Owner + Key Vault Admin across 3 subscriptions. Blast radius: full key exfiltration + resource takeover. Recommend scoping to least-privilege Reader + Key Vault Secrets User.”

IAM Risk Detection

Detect identity risks

Identify IAM misconfigurations such as unused admin permissions, principles without MFA, or identities with excessive permissions enhanced with guided remediation steps to reduce access and revoke unused permissions.

Identity Anomaly Events
Impossible TravelHigh

admin@contoso.com signed in from United States then Singapore 22 minutes later. Physical travel is impossible — potential account takeover.

Suspicious Permission GrantHigh

Add app role assignment to service principal · Add OAuth2PermissionGrant · Consent to application — 3 operations by svc-deploy in 4 minutes.

Legacy Auth ProtocolMedium

jdoe@contoso.com authenticated via IMAP4. Legacy protocols bypass Conditional Access and MFA — credential spray target.

Behavioral Detection

Identity threat detection

Quickly identify suspicious activity that could signal a compromised account — impossible travel, legacy authentication, bulk permission changes, and suspicious consent grants — detected by TENET's own heuristics against Entra ID sign-in and audit logs.

Risk event types

Every identity risk event TENET detects

Detected from Microsoft Entra ID sign-in and directory audit logs (via Microsoft Graph), Microsoft 365's own audit log for collaboration activity, and Entra ID Protection's own risk scoring where the tenant is licensed for it.

Impossible travel

A sign-in pattern implying physically impossible movement between locations.

Risky and anomalous sign-ins

Leverages Microsoft's own Entra ID Protection risk scoring where the tenant is licensed for it.

Legacy authentication use

Sign-ins using older protocols that bypass modern MFA controls.

Credential attacks

Password spray and brute-force patterns detected across accounts.

Bulk directory operations

An unusual volume of account or permission changes by one admin, baselined against their own normal activity.

Privilege and consent changes

Role grants and app consent grants, scored by what was actually granted — a tenant-wide grant of a sensitive permission ranks higher than a narrow one.

Suspicious AI agent identity sign-ins

The same sign-in detection applied to AI agent identities, not just human accounts.

Correlated multi-signal incidents

Several of the above happening to the same account in a short window — flagged as a likely account takeover.

Featured Resources

Want to learn more?
Dig into more resources.

Security
Cloud access governance for Azure: A CIEM guide
3 min read
Read article

Take control of your identity risks

Get started with Identity Security reimagined today.

FREE ASSESSMENTREQUEST DEMO

14-day free trial · No credit card required · Cancel anytime