Connect the sources.
Reveal the sequence.
From the first sign-in to the final action. One connected Microsoft 365 investigation.
Many sources.
One identity story.
Connect the sign-in to everything that follows.
Follow an identity across your Microsoft 365 environment.
Email. Files. Apps.
The same identity.
A sign-in, a mailbox change, and application consent can look unrelated in separate views. Put them into sequence and the investigation changes.
Good questions.
Clear answers.
Why isn’t location enough?+
Location describes where access appears to originate. It does not explain what an identity does after authentication. Residential proxies and stolen sessions make it important to examine behaviour alongside location.
Which sources does Sentry unify?+
Sentry connects Entra ID sign-ins and audit events, Exchange activity, SharePoint and OneDrive activity, Teams, application permissions, devices, and authentication changes. These diagrams explain the source model; the interactive tour uses sample data.
Does unified mean every event is always available?+
No. Investigation depth depends on the evidence available from the connected environment. A useful account distinguishes observed activity from gaps in the record.
See the story.
Take the next step.
Explore a connected view of identities, investigations, and evidence.