Customer Experience Overview

Customer Experience: ITDR + Log Visibility in ONE

Customers interact with ONE for onboarding, monitoring, investigations, response, and compliant log access across a single connected workflow.

Platform At A Glance

ITDR brings setup, monitoring, investigation, response, and retention into one operator experience.

End-to-end flow

Five-stage customer pipeline

1

Subscribe & Activate

Select and activate ITDR inside ONE.

Core ITDR module enabled for the tenant workspace
Subscription and entitlement confirmation in one setup flow
Guided activation for operators and administrators
2

Connect Data Sources

Connect identity and activity providers in minutes.

Microsoft 365 and Entra ID integration lanes
Credential and permission validation for ingestion
Live connection health state per source
3

Monitor ITDR

Track detections, trends, and affected identities.

Risk detections and incident volume in one dashboard
Entity-linked investigation context across logs and alerts
Connector coverage visibility while monitoring
4

Investigate Incidents

Drill down with timeline and incident evidence.

Incident queue with status and severity focus
Timeline-first evidence review for fast triage
Pivot from incident details directly into related logs
5

Respond, Search & Retain

Contain threats and keep compliance-ready log access.

Response actions such as session revoke and sign-in block
Search workflows across live and archived logs
Retention support for audits and regulatory needs

1. Subscribe and activate

Platform modules

Security Monitoring

Core module

Active

ITDR

Identity threat detection and response

Active

Cloud Security

Optional add-on

Available

Endpoint Security

Optional add-on

Available

2. Connect data sources

Integration health

Microsoft 365

Email, users, audit logs, apps

Healthy

Entra ID

Users, sign-ins, roles, privileged activity

Healthy

3. Monitor ITDR

Operational dashboard view

High Risk Detections

23

+16% vs prior 7 days

Medium Risk Detections

67

+12% vs prior 7 days

Low Risk Detections

112

+8% vs prior 7 days

Open Incidents

18

Current active incident count

4. Investigate incidents

Incident queue snapshot

HighIn progress

Privilege abuse

admin@acme.com

Entra ID

HighOpen

Suspicious sign-in

jdoe@acme.com

M365

MediumSOC triage

Impossible travel

mwhite@acme.com

Entra ID

MediumOpen

MFA enrollment anomaly

svc-backup@acme.com

Entra ID

5. Respond and contain

Response actions

Disable account
Revoke sessions
Require password reset
Block sign-in
Assign owner
Open workflow

Search, analytics and retention

Operator reporting tools

Detection trends
Risk overview
User risk score
Executive summary
Identity posture and hygiene
Data export (reports and logs)

Log lifecycle in ONE

Recent logs (24h)

Latest activity is immediately available for monitoring and investigation.

Archived logs

Logs older than 24 hours move into secure archive storage.

Search and investigation

Operators can search live and archived data in one connected workflow.

Customer journey

1Subscribe
2Connect
3Monitor
4Investigate
5Search Logs
6Respond