Skip to content

Detect and Respond

Identity Compromise

Catches impossible travel, MFA fatigue, and credential stuffing, and contains the account before it becomes lateral movement.

Audience
SOC analysts
Headline
Accounts contained
Sources
Identity, MFA, audit logs
Output
Contained accounts

What it does

Inside Identity Compromise

Account-takeover detection across sign-in, MFA, and audit telemetry, with containment on approval.

Takeover pattern detection

Impossible travel, MFA fatigue, credential stuffing, and unfamiliar-infrastructure sign-ins, correlated rather than alerted one by one.

Per-account risk scoring

A score per identity that accounts for privilege level, recent behaviour, and whether that account has been targeted before.

Cross-agent correlation

A user who clicked a phishing link and then signed in from somewhere new is one story, not two unrelated alerts.

Containment on approval

Revoke sessions, force a password reset, require re-registration of MFA, or disable the account. Proposed, then approved.

Conditional access awareness

The agent reads your policies, so a proposed containment never conflicts with a policy already covering it.

Monitoring without action

Unusual but explainable behaviour is watched rather than actioned, ready to escalate if the pattern continues.

How it works

See, decide, act.

Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.

  1. See

    How every account is behaving

    Sign-in logs, risk detections, MFA events, and audit activity, read continuously rather than sampled.

    • Entra ID sign-in logs
    • Entra ID Protection risk detections
    • MFA event logs
    • Microsoft 365 audit activity
    • Okta system log
  2. Decide

    Correlated into a risk score

    Patterns are correlated across sources and scored per identity, weighted by privilege and by anything already known about that user.

    • Impossible travel between sign-ins
    • Repeated MFA denials then an approval
    • A password spray across many accounts
    • A phishing click on the same user
  3. Act

    Contained, or watched

    High-risk accounts get a proposed containment set for approval. Medium-risk accounts go to monitoring, with the escalation trigger recorded.

    • Revoke all refresh tokens
    • Force password reset
    • Require MFA re-registration
    • Disable the account
    • Monitor and re-evaluate
1 / 3

Governance

How Identity Compromise is governed

What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.

What it does on its own

Reads all identity telemetry, correlates patterns, scores every identity, and places medium-risk accounts under monitoring.

What always waits for a person

Revoking sessions, forcing a reset, requiring MFA re-registration, and disabling an account all require analyst approval.

What it records

The signals behind the score, the correlation path, the approval, the containment executed, and the account's state after.

Alert Navigator

Detect and Respond · v2.0

Alert triage that separates true from false positives, groups related alerts into cases, and opens the ticket.


  • Pending triage
  • True positives
  • Tickets opened

Phishing Remediation

Detect and Respond · v2.0

Multi-source phishing triage with enrichment, mailbox scoping, and analyst-gated remediation.


  • Awaiting decision
  • Incidents handled
  • Actions reversed

Book a demo

See Identity Compromise on your own data.