battle tested
Battle-tested
Rule has produced real alerts/incidents in tenant scope and is operationally validated.
Public reference
This page separates detection quality validation from the main detection catalog. It shows how rules are classified as battle-tested, blocked, degraded, or waiting for signal so product, engineering, and SOC teams can agree on readiness before claiming production coverage. Feed rows now include explicit operator states: core healthy, core degraded, enrichment degraded, and auth broken.
battle tested
Rule has produced real alerts/incidents in tenant scope and is operationally validated.
monitoring
Prerequisite telemetry is present, but no qualifying behavior fired in the selected lookback window.
no signal
Required telemetry has low/zero event volume so detections cannot be confidently evaluated yet.
degraded
Sync/import quality issues are reducing confidence or timeliness for one or more prerequisite feeds.
blocked
Licensing/permission/authorization gaps are preventing prerequisite telemetry ingestion.
License clarity
- Business Premium includes Entra P1 baseline. Core sign-in/audit detections can still be healthy even when optional risk/security feeds warn.
- Entra P1 / Microsoft 365 E3 generally aligns with the same core telemetry coverage as Business Premium for this ITDR model.
- Entra P2 / Microsoft 365 E5 improves risk-detail depth and enrichment quality but does not replace connector permission requirements.
- Treat feed-level evidence as source of truth. A connector-level warning headline can coexist with healthy core sign-in ingestion.
How to generate validation signal
- Generate failed + successful sign-ins: attempt invalid sign-ins, then successful sign-in from user account to produce sequence patterns.
- Generate risky identity actions: update MFA methods, reset passwords, and review risky sign-in outcomes in Entra ID logs.
- Generate directory-audit signals: approve/revoke app consent, change app credentials, and role assignments from Entra admin center.
- Generate O365 mailbox-rule signals: create test forwarding/move/delete inbox rules in Exchange admin for validation scenarios.