Take a closer look.
No tenant connection needed.
Explore a sample workspace. Switch views, find an environment, and follow the illustrative activity behind an identity.
One incident.
The whole picture.
Follow a suspicious sequence from the first signal to a considered response.
A familiar session. An unfamiliar sequence.
- Session reusedEntra ID
Familiar location; access succeeds.
- Forwarding rule createdExchange
External forwarding is new for this identity.
- Application consent grantedApplications
A new application gains ongoing access.
An unfamiliar combination of actions merits investigation, even when the IP address looks routine.
Review the connected evidence and the user’s normal activity before deciding what happens next.
- Contain access
Revoke the session under the agreed policy.
- Remove persistence
Remove the forwarding rule and unauthorised app access.
- Record the outcome
Keep evidence, actions, and follow-up work together.
Workspace overview
Choose an environment. Follow an identity. See the evidence.
Connected environments
No results match your filters.
Good questions.
Clear answers.
Is this live security data?+
No. All organisations, identities, counts, and events in this tour are illustrative. They do not represent live monitoring or an actual incident.
Does the tour change my Microsoft 365 environment?+
No. The tour does not authenticate with Microsoft 365, connect a tenant, or take any response action.
What can I try here?+
Select an environment, browse its identities, and explore the evidence. Search and filter activity, expand an event for context, and return to the overview at any time.