Public knowledge base
Setup guides for real user workflows
Step-by-step reference for connector configuration, permissions, tenant and user onboarding, and report generation — written to reduce setup friction for customer admins and partner operators.
New here? Start with the onboarding checklist
The recommended order for tenant setup, connectors, validation, and reporting.
Onboarding
1 article
Operations
3 articles
Identity Risk dashboards — permissions & licensing
What the Identity Risk page needs from your Microsoft connector: the Graph permissions behind each security check, what Entra Free / P1 / P2 tenants can assess, and how each connector mode (auto-managed, app-only, delegated) covers it.
Updated June 11, 2026 · 7 min
VIP watchlist
Mark VIP identities (CEO, CFO, admins) so any detection alert against them auto-escalates severity by one tier and gets a visible VIP marker for fast SOC routing.
Updated May 15, 2026 · 4 min
Notification channels setup
Configure Slack, Microsoft Teams, or PagerDuty delivery for ITDR alerts, incidents, connector health, and response-action outcomes.
Updated May 6, 2026 · 13 min
Connector setup
6 articles
Microsoft connector (auto-managed mode)
One-click Global Admin sign-in that auto-provisions a dedicated app registration in the customer tenant with all required Graph, Exchange Online, and Teams permissions — including posture and response-action workloads.
Updated May 15, 2026 · 8 min
Microsoft connector (delegated mode)
Set up delegated Microsoft ingestion, understand consent scopes, and validate both Graph and Office 365 lanes.
Updated May 5, 2026 · 10 min
Microsoft connector (app-only mode)
Use client credentials for tenant ingestion, map required Graph application permissions, and verify stable background sync.
Updated May 5, 2026 · 10 min
Okta connector (API token)
Add an Okta tenant with an admin API token. Required scopes, where to generate the token, what ITDR ingests, detection rule coverage, and how containment runs on Okta-linked incidents.
Updated May 16, 2026 · 9 min
Okta connector (OAuth admin consent)
Add an Okta tenant via OAuth 2.0 + admin consent. Registering the OAuth client in Okta, scopes, the redirect URI, refresh-token rotation, and when to choose this over API token.
Updated May 19, 2026 · 8 min
Okta connector (Service App / private-key JWT)
Add an Okta tenant via a Service App using private-key JWT client auth. Generating the key pair, registering the Service App in Okta admin, scopes, and uploading the public key (JWK).
Updated May 19, 2026 · 9 min
Posture setup
2 articles
Okta posture findings
How ITDR scans Okta for admin role inventory, MFA coverage, password policy, lockout policy, sign-on MFA enforcement, and stale super-admins. Cadence, scopes, and what each finding means.
Updated May 19, 2026 · 7 min
Posture credentials setup
Prepare Azure or Microsoft 365 posture credentials and map each input field required by the Posture connector form.
Updated May 5, 2026 · 9 min
Detection
2 articles
Custom detection rules
Author your own sign-in detection rules without code changes — pick fields, operators, threshold, window, and group-by, then activate from the rules table.
Updated May 15, 2026 · 6 min
OAuth / workload-identity abuse detection
Four new detections shipped against OAuth and service-principal abuse: device-code phishing, credential-add persistence, vendor brand mimicry, and application-vs-delegated permission risk weighting.
Updated May 26, 2026 · 8 min
User access
1 article
Reporting
2 articles
One-time security assessment report
Generate a point-in-time identity security assessment, review the snapshot, and export the report as PDF.
Updated April 27, 2026 · 6 min
Weekly security report
Review the weekly tenant report from Dashboard and download the PDF for customer and SOC stakeholder updates.
Updated April 27, 2026 · 6 min
Compliance
4 articles
Compliance evidence aggregator
How ITDR turns Microsoft 365 posture findings into auditor-ready compliance evidence across CIS, ISO 27001, HIPAA, CMMC, and CIS IG1.
Updated May 26, 2026 · 7 min
Compliance framework coverage
Per-control breakdown for all 6 supported frameworks: which controls auto-reconcile from posture findings and which always need a manual attestation. Auditor- and partner-facing one-pager.
Updated May 28, 2026 · 10 min
HIPAA Security Rule mapping
Which HIPAA standards ITDR maps automatically from posture findings, which need manual attestation, and how to prepare for an audit.
Updated May 26, 2026 · 8 min
Audit packages
Generate an auditor-ready PDF audit package from your compliance evidence — scope, structure, and how to read it.
Updated May 26, 2026 · 5 min