Public coverage guide

Microsoft license coverage for ITDR

Clear view of what you get versus what is limited across Business Premium, Entra P1 / Microsoft 365 E3, and Entra P2 / Microsoft 365 E5. This is designed to remove connector setup ambiguity for PM, engineering, and SOC teams.

Last reviewed

April 22, 2026

Coverage labels represent current product behavior with tenant feed prerequisites, not marketing-only SKU claims.

New to Microsoft licensing? Start with the plain-English explainer.

What changed recently

Feed readiness guidance now aligns with explicit states used in detection validation pages.
Coverage copy is synchronized with current connector behavior and warning handling.

Coverage matrix

What users get by tier

ITDR featureBusiness Premium (includes P1)Entra P1 / M365 E3Entra P2 / M365 E5Notes
Sign-in and directory audit detectionsCoreCoreCoreCore ITDR behavior. Requires Graph permissions and connector health, not premium risk SKUs.
Office 365 mailbox-rule detectionsCoreCoreCoreRequires separate Office 365 Management consent and unified audit availability.
Risk-enriched sign-in contextPartialPartialEnhancedNon-P2 tenants can return hidden or generic risk context. P2 gives richer risk detail.
Risky users and risk detections APIsPartialPartialEnhancedMay be limited by tenant entitlement and role/permission setup. Treat as enrichment lane.
Security alerts/incidents ingestion from Graph security APIsDependsDependsEnhancedDepends on Defender/XDR provisioning and entitlement, not only connector auth mode.
Containment actions (disable user, revoke sessions, group removal)CoreCoreCoreDepends on Graph permissions and admin consent. Not blocked by P2-only risk features.

Expected warnings

What warnings usually mean

identityProtection/riskyUsers -> 403 Forbidden

Tenant entitlement does not expose this risk feed at the expected depth.

Action: Keep core detections active; treat risk enrichment as partial unless upgrading entitlements.

security/alerts_v2 or /security/incidents -> 403 Unauthorized account not provisioned

Defender security workload is not provisioned for that tenant plan/config.

Action: Do not classify core sign-in/audit telemetry as down; mark security-provider feed as unavailable.

o365_management token fallback or 401 errors

Connector could not use tenant O365 delegated token path reliably.

Action: Run O365 consent for that connector again and verify feed subscription state.

Connector sync status shows synced_with_warnings

One or more optional feeds warned, even while core telemetry may still be flowing.

Action: Check feed-specific run status and event counts before treating tenant as fully degraded.

Microsoft UI checklist

How to unlock expected coverage

Microsoft Entra -> Enterprise applications -> ensure required Graph permissions are admin-consented.
ITDR Connectors -> run Graph delegated/app-only setup, then run separate O365 consent for O365 Management feed.
Microsoft Purview / Audit settings -> verify unified audit logging is enabled for the tenant.
Microsoft Entra -> Licensing -> confirm tenant/user SKU baseline (Business Premium/P1/E3/P2/E5) matches expected depth.
Re-run ad hoc Sync now and validate feed-by-feed readiness, not only connector headline status.

Official references

Microsoft Entra licensingEntra sign-in and audit data retentionGraph riskDetections APIOffice 365 Management Activity API