Documentation

Security Suite · Guides

Identity protection

Detect account takeover and risky sign-ins in concert with your SSO provider — impossible-travel and MFA-fatigue detection, risk-based response, and how identity signals reach the SOC.

Identity is the new perimeter. Identity protection watches sign-ins and account activity through your SSO provider to catch account takeover — the step most attacks now depend on. What it finds rolls up into the Suite's wider view of identity risk, MFA gaps, and attack paths across Entra ID, Active Directory, and Google Workspace.

What it detects

  • Impossible travel — sign-ins from two places too far apart, too fast.
  • MFA fatigue / push bombing — repeated MFA prompts aimed at getting a user to approve one by mistake.
  • Anomalous sign-ins — new device, location, or ASN that doesn't match the user's baseline.
  • Risky changes — new MFA methods, mailbox forwarding rules, or OAuth grants that often follow a takeover.
  • Dormant & privileged account misuse — activity on accounts that shouldn't be active, or privilege used in unusual ways.

Risk-based response

Each session gets a risk score. You decide what happens at each level:

RiskTypical response
LowAllow, log.
MediumStep-up MFA or require re-authentication.
HighBlock the session and/or force a password reset.
Confirmed takeoverDisable the account; the SOC investigates.

Responses run through your identity provider (for example, Microsoft Entra ID), so enforcement uses the controls you already have.

Works with the rest of the Suite

Identity signals correlate with endpoint and email events in the Managed SOC: a phishing email → a risky sign-in → a suspicious process on a laptop becomes one case, not three alerts.

Connect your identity provider

Link your SSO so identity protection can read sign-in and audit logs and push responses back.

Set risk responses

Map risk levels to actions (step-up MFA, block, disable) in Security Suite → Identity.

Tune baselines

Give it a short learning window so per-user location and device baselines settle, reducing false positives.

Keep a break-glass admin

Before enabling automatic account-disable responses, ensure a break-glass admin account is excluded, so an aggressive rule can never lock every administrator out. See roles & permissions.

Need a hand with Security Suite?Talk to our team →