Public reference

Detection validation matrix

This page separates detection quality validation from the main detection catalog. It shows how rules are classified as battle-tested, blocked, degraded, or waiting for signal so product, engineering, and SOC teams can agree on readiness before claiming production coverage. Feed rows now include explicit operator states: core healthy, core degraded, enrichment degraded, and auth broken.

battle tested

Battle-tested

Rule has produced real alerts/incidents in tenant scope and is operationally validated.

monitoring

Monitoring

Prerequisite telemetry is present, but no qualifying behavior fired in the selected lookback window.

no signal

No signal

Required telemetry has low/zero event volume so detections cannot be confidently evaluated yet.

degraded

Degraded

Sync/import quality issues are reducing confidence or timeliness for one or more prerequisite feeds.

blocked

Blocked

Licensing/permission/authorization gaps are preventing prerequisite telemetry ingestion.

License clarity

How to interpret readiness by tier

- Business Premium includes Entra P1 baseline. Core sign-in/audit detections can still be healthy even when optional risk/security feeds warn.

- Entra P1 / Microsoft 365 E3 generally aligns with the same core telemetry coverage as Business Premium for this ITDR model.

- Entra P2 / Microsoft 365 E5 improves risk-detail depth and enrichment quality but does not replace connector permission requirements.

- Treat feed-level evidence as source of truth. A connector-level warning headline can coexist with healthy core sign-in ingestion.

How to generate validation signal

Microsoft UI actions for prereq telemetry

- Generate failed + successful sign-ins: attempt invalid sign-ins, then successful sign-in from user account to produce sequence patterns.

- Generate risky identity actions: update MFA methods, reset passwords, and review risky sign-in outcomes in Entra ID logs.

- Generate directory-audit signals: approve/revoke app consent, change app credentials, and role assignments from Entra admin center.

- Generate O365 mailbox-rule signals: create test forwarding/move/delete inbox rules in Exchange admin for validation scenarios.