Identity is the new perimeter. Identity protection watches sign-ins and account activity through your SSO provider to catch account takeover — the step most attacks now depend on. What it finds rolls up into the Suite's wider view of identity risk, MFA gaps, and attack paths across Entra ID, Active Directory, and Google Workspace.
What it detects
- Impossible travel — sign-ins from two places too far apart, too fast.
- MFA fatigue / push bombing — repeated MFA prompts aimed at getting a user to approve one by mistake.
- Anomalous sign-ins — new device, location, or ASN that doesn't match the user's baseline.
- Risky changes — new MFA methods, mailbox forwarding rules, or OAuth grants that often follow a takeover.
- Dormant & privileged account misuse — activity on accounts that shouldn't be active, or privilege used in unusual ways.
Risk-based response
Each session gets a risk score. You decide what happens at each level:
| Risk | Typical response |
|---|---|
| Low | Allow, log. |
| Medium | Step-up MFA or require re-authentication. |
| High | Block the session and/or force a password reset. |
| Confirmed takeover | Disable the account; the SOC investigates. |
Responses run through your identity provider (for example, Microsoft Entra ID), so enforcement uses the controls you already have.
Works with the rest of the Suite
Identity signals correlate with endpoint and email events in the Managed SOC: a phishing email → a risky sign-in → a suspicious process on a laptop becomes one case, not three alerts.
Connect your identity provider
Link your SSO so identity protection can read sign-in and audit logs and push responses back.
Set risk responses
Map risk levels to actions (step-up MFA, block, disable) in Security Suite → Identity.
Tune baselines
Give it a short learning window so per-user location and device baselines settle, reducing false positives.
Keep a break-glass admin
Before enabling automatic account-disable responses, ensure a break-glass admin account is excluded, so an aggressive rule can never lock every administrator out. See roles & permissions.
