Expected warnings
What warnings usually mean
identityProtection/riskyUsers -> 403 Forbidden
Tenant entitlement does not expose this risk feed at the expected depth.
Action: Keep core detections active; treat risk enrichment as partial unless upgrading entitlements.
security/alerts_v2 or /security/incidents -> 403 Unauthorized account not provisioned
Defender security workload is not provisioned for that tenant plan/config.
Action: Do not classify core sign-in/audit telemetry as down; mark security-provider feed as unavailable.
o365_management token fallback or 401 errors
Connector could not use tenant O365 delegated token path reliably.
Action: Run O365 consent for that connector again and verify feed subscription state.
Connector sync status shows synced_with_warnings
One or more optional feeds warned, even while core telemetry may still be flowing.
Action: Check feed-specific run status and event counts before treating tenant as fully degraded.