A clearer view of account security

Know which sign-ins need your attention.

Bring Microsoft 365 sign-in activity, risk signals and account history together. Give your team the context to investigate unusual access and make informed decisions.

Built for the people responsible for Microsoft 365 security.

Security overviewIllustrative example

ACCOUNT ACTIVITY

A pattern worth reviewing.

Today
12accounts involved
24failed attempts
1successful sign-in
Repeated failures

One source tries several accounts.

Failed
A sign-in succeeds

Same source. One of the targeted accounts.

Success
Suspected password spray

The sequence matters more than either event alone.

From individual events to a useful explanation.
Microsoft 365 sign-insRelated-event analysisScoped trust rulesClear security reporting

The context behind the activity

The log tells you what happened.
The context helps you decide what to do.

A new location might be a business trip. A failed login might be a typo. Looking at the account, network and surrounding activity helps your team distinguish routine changes from something that needs investigation.

01 / UNDERSTAND

See why an alert was raised.

Review the signals behind a finding, from unfamiliar locations and risky networks to unusual authentication patterns. Follow the evidence back to the underlying sign-ins.

02 / INVESTIGATE

Keep the wider history in view.

Use a searchable timeline, location view and retained sign-in records to understand what came before an alert and whether the same pattern has appeared before.

03 / REFINE

Make exceptions with boundaries.

Account for known networks and expected activity with scoped trust rules. Give exceptions an expiry date so yesterday’s explanation doesn’t become a permanent blind spot.

See the difference context makes

Familiar situations.
A more informed response.

Explore three examples of what your team can investigate. These scenarios use fictional activity to explain the product’s approach.

When failures become a pattern

Twelve accounts.
One source.
Then a successful sign-in.

A handful of failures on one account could be an ordinary mistake. Similar attempts across several accounts tell a different story.

UserDefend 360 connects related attempts and highlights when a targeted account later signs in successfully from the same source.

Your next step

Review the successful sign-in and confirm it with the account owner. Use your Microsoft Entra controls if action is needed.

EXAMPLE INVESTIGATIONCritical

Suspected password spray

One source · 12 accounts · 8 minutes

  1. The attempts begin

    Failed sign-ins appear across multiple accounts from 203.0.113.42.

  2. The pattern becomes visible

    24 failed attempts involve 12 different accounts.

  3. One targeted account signs in

    A successful sign-in follows from the same source.

When another prompt deserves a question

Six MFA rejections.
Then access is granted.

An employee rejects several authentication requests. A successful sign-in follows shortly afterwards. Did they finally complete a legitimate login, or approve a prompt they didn’t initiate?

UserDefend 360 groups repeated MFA rejections and highlights a subsequent success so your team can follow up with the account owner.

Your next step

Ask whether the employee initiated the requests. Review the sign-in and registered MFA methods before deciding how to respond.

EXAMPLE INVESTIGATIONCritical

Suspected MFA fatigue

One account · repeated MFA rejections

  1. Authentication is rejected

    The first MFA challenge is not completed.

  2. More rejections follow

    Six MFA failures are recorded for the same account.

  3. A sign-in succeeds

    Access is granted after the sequence of rejections.

When the locations don’t add up

Zurich to Singapore.
In eighteen minutes.

The same account signs in from two locations thousands of kilometres apart. That deserves a closer look, but the explanation could be a VPN rather than an intruder.

UserDefend 360 compares geolocated sign-ins and surfaces implausible travel alongside network and account context.

Your next step

Check the network and confirm the activity with the user. If a known VPN explains it, consider a narrowly scoped trust rule.

EXAMPLE INVESTIGATIONRisk signal

Implausible travel

One account · two distant locations

Zurich14:02 UTC
18 minutes
Singapore14:20 UTC
Distance
Approximately 10,300 km
What to check
VPN, network and user activity

The right detail for each audience

A clear update.
A useful starting point.

Keep reviewers focused on what changed and what remains open. Configure security alerts and scheduled digests for the people who need them.

  • For the people investigatingAlert details, contributing signals and links back to the console.
  • For the people staying informedDigest summaries of activity and alerts, with account-level detail kept out of the email.
  • For a closer lookLinked reports with optional password protection for additional detail.
Clarity, from the console to the inbox
UserDefend 360

SECURITY DIGEST · ILLUSTRATIVE EXAMPLE

The week in view.

Example organization · 28 Sep – 4 Oct

8new alerts
5resolved
3from earlier periods
What needs attention

Review new activity and revisit the alerts that remain open from earlier periods.

Open the detailed report Example only. No customer data is shown.

A practical place in your workflow

Connect. Understand. Investigate.

UserDefend 360 helps your team review activity and decide on a response. Your existing Microsoft identity controls remain where you take action.

  1. 01

    Connect your organization.

    Set up an authorized connection to your Microsoft 365 sign-in data. We help confirm the permissions and data available for your environment.

  2. 02

    Put activity in context.

    Scheduled collection and analysis bring sign-ins, location and network context, risk signals and related events into one view.

  3. 03

    Review and respond.

    Investigate the findings, record what you know and refine trust rules. Take any account or access-control action in Microsoft Entra.

Before you get started

A few useful answers.

Have a question about your environment?
Talk to our team

Does UserDefend 360 block suspicious sign-ins?

No. It helps you detect and investigate unusual activity. Your team decides on the response and uses Microsoft Entra or other existing controls to manage access, revoke sessions or secure an account.

Will every unusual sign-in generate an alert?

No. The system evaluates available signals and related activity. Scoped trust rules help account for known networks and expected behaviour. An alert indicates something worth reviewing; it is not proof of a compromise.

How quickly does new activity appear?

Activity appears after each scheduled collection and analysis cycle. The configured interval and Microsoft’s data availability determine how quickly a sign-in can be reviewed. We’ll help you choose a suitable setup.

What do we need to connect Microsoft 365?

An authorized connection to your organization’s sign-in data. Available records and connection options depend on your Microsoft licensing and permissions. We review these requirements with you during setup.

Can we review more than one organization?

Yes. The console supports multiple tenants, with an active-tenant selector to keep each organization’s activity and settings in context.

How do we get started?

Contact us for a walkthrough of the product and a discussion of your environment. Access is provisioned by an administrator. Existing users can sign in to the console.

Let’s look at your environment

Make your next security
review more informed.

Tell us how you manage Microsoft 365 today. We’ll show you where UserDefend 360 can help.

Arrange a walkthrough