1. High-risk app permission or governance change
Inspect directory audit events and match sensitive governance keywords.
- Review audit event and approval context.
- Inspect workload permissions and linked posture findings.
Public reference
This page documents all current ITDR built-in detections from the live rule engine so your incident response team can review trigger logic, thresholds, grouping, and evidence expectations.
View mode
Executive mode highlights business impact, priority, and remediation guidance.
Detection coverage model
Rule behavior is validated against live Microsoft telemetry, then alerts are grouped into incidents through the same investigation workflow used in the platform.
Office 365 Management telemetry supports both native mailbox-rule detections and mapped SecurityCompliance/threat signals.
Office 365 Management coverage model
This catalog includes built-in Exchange mailbox-rule detections. In addition, the platform ingests Office 365 Management content types (`Audit.AzureActiveDirectory`, `Audit.Exchange`, `Audit.SharePoint`, `Audit.General`, `DLP.All`) and maps SecurityCompliance/threat-related records into alerts with source `o365_management`.
Subscription-level failures are warning-classified. If one content type is unavailable (for example `DLP.All`), other enabled content types can still ingest.
Licensing realism
This matrix reflects current platform behavior and production observations as of April 22, 2026. Microsoft licensing and tenant entitlements can change; this page is an operational guide, not a legal licensing contract.
Microsoft references: Business Premium security overview | Entra risk detection licensing | Entra log retention by tier
Operational expectations
Prevent initial login
Identity platform controls
Conditional Access, phishing-resistant auth, device compliance, and browser/DNS controls stop many attacks before account session establishment.
Detect compromise patterns
ITDR detections (this catalog)
The rules on this page detect suspicious identity and workload behavior from Graph telemetry and correlated context; provider-originated Office 365 alerts are mapped separately.
Contain and respond
Platform response workflow
Capability-aware actions, verification, and immutable action history reduce dwell time after a suspicious event is observed.
Executive detection view
Priority model
Detections are score-driven. Higher scores represent higher response urgency and should be triaged first.
Business value
Focuses SOC effort on likely compromise patterns and concrete containment paths instead of raw event volume.
Operational caveat
Detection timing still depends on Microsoft log publication latency and connector health.
28 rules
Inspect directory audit events and match sensitive governance keywords.
- Review audit event and approval context.
- Inspect workload permissions and linked posture findings.
Start from sensitive audit candidates.
- Validate onboarding approval and ownership.
- Remove unnecessary high-risk grants.
Start from sensitive audit candidates.
- Assign accountable owner(s) immediately.
- Rotate credentials and remove unneeded high-risk permissions.
Group consent/grant keyword events per entity (application or service principal).
- Validate all grants/consents in the burst.
- Remove unauthorized delegated/app permissions.
Group failed sign-ins by identity and app context.
- Validate if failures are expected.
- Revoke sessions if unauthorized.
Group service principal sign-in events by app_id.
- Confirm with the application owner whether this integration is still in use.
- If in use, rotate the expired client secret in the Azure AD app registration and update the application configuration.
Pair each successful INTERACTIVE sign-in with successful NON-INTERACTIVE sign-ins for the same identity within the next 30 minutes.
- Revoke active sessions for the identity to invalidate any captured tokens.
- Reset the user's password and require re-registration of MFA methods.
Require successful sign-in.
- Validate user intent and device/session context.
- Revoke sessions and force reauth if unauthorized.
Start from successful sign-ins.
- Validate if success was expected after failure burst.
- Revoke sessions if spray/replay pattern suspected.
Start from successful interactive sign-ins with normalized location.
- Validate user travel legitimacy.
- Revoke sessions if activity is unexplained.
Group successful non-interactive sign-ins by identity and app key.
- Validate expected automation/background token usage.
- Revoke sessions/refresh tokens if unauthorized.
Start from successful non-interactive sign-ins.
- Validate session/token context for expected automation.
- Revoke sessions if unexpected non-interactive usage appears.
Group failed sign-ins by public source IP address.
- Treat as password spray or credential stuffing until disproven.
- Block/challenge source IP and validate conditional access behavior.
Group successful sign-ins by public source IP address.
- Validate whether the source infrastructure is approved.
- Investigate affected users for token misuse or session theft patterns.
Inspect Office 365 Management Exchange events for inbox-rule operations.
- Review and disable suspicious inbox rules.
- Inspect forwarding/redirect settings and mailbox access history.
Start from suspicious Exchange inbox-rule manipulation.
- Remove or disable suspicious mailbox filter rules immediately.
- Validate whether user received/acted on concurrent phishing content.
Start from suspicious Exchange inbox-rule manipulation.
- Treat as potential active BEC attempt and isolate mailbox quickly.
- Review recent sent/forwarded/deleted finance communications.
Start from suspicious Exchange inbox-rule manipulation.
- Remove suspicious rules and inspect account for phishing foothold indicators.
- Check for linked identity changes and suspicious OAuth grants.
Correlate risky sign-in detection with authentication-method change event on same identity.
- Contain identity immediately (revoke sessions, reset credentials, validate MFA methods).
- Remove mailbox persistence and investigate scope of compromise.
Start from credential theft spray alert keyed to source IP.
- Block/challenge source infrastructure and enforce step-up controls.
- Contain impacted identities and review additional persistence attempts.
Aggregate non-interactive token replay alerts by shared source IP.
- Treat as possible token theft campaign spanning multiple identities.
- Revoke active sessions/tokens across affected identities.
Start from successful sign-ins and look back for prior failures on the same identity and app context.
- Treat this as potential MFA push-fatigue/challenge manipulation until user intent is verified.
- Revoke sessions and require reauthentication if legitimacy is unclear.
Start from risky successful sign-in detections for an identity.
- Validate whether the authentication-method change was expected and approved by the user.
- Revoke sessions and reset credentials if sign-in legitimacy is uncertain.
Start from risky successful sign-in detections for an identity.
- Validate whether the password reset/change was initiated by the legitimate user.
- Revoke sessions and force secure credential reset if legitimacy is uncertain.
Start from risky successful sign-in detections for an identity.
- Validate whether the OAuth consent or permission grant was explicitly approved.
- Revoke unauthorized delegated/app grants and disable suspicious workload identities.
Start from risky successful sign-in detections for an identity.
- Treat as potential MFA-bypass persistence and validate user intent immediately.
- Revoke sessions and require strong MFA method re-registration.
Start from risky successful sign-in detections for an identity.
- Revoke newly assigned privileged roles until approval context is confirmed.
- Contain actor identity and invalidate active sessions/tokens.
Evaluate older workload identities (service principals) for newly observed recent sign-in activity.
- Validate ownership/business intent for this workload identity activation.
- Review and roll back unauthorized credential/permission changes.