First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Risky Users and Risky sign-ins monitoring
Security

Risky Users and Risky Sign-Ins Monitoring — Microsoft Entra ID

Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.

Timeline 30 daysService owner Roman Sotnik

What this engagement is

This service helps customers monitor risky users and risky sign-ins in a Microsoft 365 environment. IT Partner engineers use Microsoft tools and security signals to identify users at risk, risky sign-in history, detection details, risk history, and cases where risk was remediated or dismissed.

Success criteria

01This service is provided on an ongoing basis, free of charge for IT Partner clients.
02The service results in the customer's full awareness of what is happening across different parts of the organization.
03Risky Users and Risky sign-ins monitoring includes tracking identified risks, discovery of new risks, evaluating risk process effectiveness, and successful risk management throughout the project.

What you receive

Recurring monitoring of risky users and risky sign-ins.
Monitoring of user activity and signals from security tools to identify events that merit attention.
Prioritization, selection, and further investigation of the most important alerts.
Real security incidents passed to the customer.
Assessment of the attack and mitigation steps.
Additional forensic data gathered.
Finalized auditing and documentation.
Response to suspicious attempts.
Communication of risk and performance data to the customer.
Information about which users are at risk, have had risk remediated, or have had risk dismissed.
Details about detections.
History of all risky sign-ins.
Risk history.

How the work unfolds

Customer connection

The customer connects to IT Partner monitoring system.

Recurring monitoring

IT Partner engineers manage recurring monitoring of risky users and risky sign-ins.

Prerequisites

Microsoft 365 tenant

Who does what

IT Partner

  • IT Partner monitors user activity, and signals from security tools to identify events that merit attention and leverage machine learning and behavioral analytics to reduce false positives and alert fatigue, discover hard-to-detect complex events like lateral movement, insider threats and data exfiltration.
  • IT Partner prioritizes, selects the most important alerts, and investigates them further. Real security incidents are passed to the customer.
  • IT Partner staff assesses the attack and mitigation steps, gathers additional forensic data and finalizes auditing and documentation.

Your team

  • The customer connects to IT Partner monitoring system.
  • Maintain the Microsoft 365 and Microsoft Entra licensing required for the risk signals, audit logs, and identity protection features used by the monitoring service.
  • Provide or approve the required delegated access, security-reader permissions, monitoring connector consent, and other tenant access needed for IT Partner engineers to perform the service.
  • Identify customer security, IT, and business contacts for incident notification, escalation, and approval of any customer-side actions.
  • Review escalated incidents, confirm business context, and authorize remediation actions such as password reset, MFA registration enforcement, account blocking, or conditional access changes when those actions are outside the pre-approved scope.
  • Maintain accurate user, administrator, and service account ownership information so risky-user findings can be triaged correctly.
  • Notify IT Partner about planned identity changes, migrations, administrator changes, known high-risk activities, or exceptions that may affect risk scoring or investigation context.

What's not included

Microsoft 365, Microsoft Entra ID, Microsoft Defender, or other license costs are not included in the per-seat monitoring fee.
Initial tenant security hardening, conditional access design, MFA rollout, identity protection policy deployment, or broader Microsoft 365 security configuration changes are not included unless separately scoped.
Full incident response, breach containment, malware removal, endpoint recovery, identity reconstruction, or business continuity recovery activities are not included beyond the monitoring, alert prioritization and investigation, incident handoff, assessment of attack and mitigation steps, forensic-data gathering, auditing, and documentation described for this service.
Monitoring of non-Microsoft 365 systems, endpoints, servers, network devices, third-party SaaS platforms, or external SIEM/SOC data sources is not included unless separately integrated and contracted.
24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and Microsoft support escalation channels when separately purchased and stated in the customer agreement.
Legal, regulatory, cyber-insurance, litigation, law-enforcement, or formal digital-forensics expert witness services are not included.
End-user security awareness training, phishing simulations, or communications campaigns are not included unless purchased as a separate service.
Custom report development, compliance audit certification, or executive governance workshops are not included unless separately scoped.

Limitations & technical notes

!Monitoring quality depends on the Microsoft 365 and Microsoft Entra signals, audit logs, retention period, and licensing available in the customer tenant.
!Microsoft risk detections use Microsoft security signals, machine learning, and behavioral analytics. They can reduce noise but cannot eliminate all false positives or false negatives.
!This service improves visibility and escalation of risky users and risky sign-ins, but it does not guarantee prevention of every account compromise, data loss event, or unauthorized sign-in.
!Historical investigation may be limited by log retention, audit configuration, and data available before onboarding to the IT Partner monitoring system.
!Some remediation options, such as forcing password reset, blocking sign-in, requiring MFA, or changing conditional access policy, may require customer approval and may affect end users.
!The service is focused on Microsoft 365 identity and sign-in risk monitoring. Broader endpoint, network, application, or cloud workload compromise may require additional tools and services.
!Availability of monitoring data may be affected by Microsoft service health issues, API throttling, tenant configuration changes, or removal of required permissions.
!Customer privacy, legal, HR, and regulatory obligations for investigating users and handling security incidents remain the customer’s responsibility.

Frequently asked questions

What is Risky Users and Risky Sign-ins Monitoring?

Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.

What does IT Partner monitor in this service?

IT Partner monitors risky users, risky sign-ins, user activity, and signals from Microsoft security tools in the customer’s Microsoft 365 environment. The monitoring includes information about users currently at risk, users whose risk was remediated or dismissed, detection details, risky sign-in history, and overall risk history.

How much does Risky Users and Risky Sign-ins Monitoring cost?

The service is listed as free of charge for IT Partner clients. There is no separate monitoring fee; confirm eligibility and onboarding steps with IT Partner before the service starts.

Is this a one-time assessment or an ongoing managed service?

Risky Users and Risky sign-ins monitoring is an ongoing managed service, not a one-time assessment. It runs on a recurring basis — free of charge for IT Partner clients — so new risky users, risky sign-ins, and risk history are monitored over time.

What prerequisites are required before starting the service?

The stated prerequisite is that the customer must have a Microsoft 365 tenant. The customer also needs to connect to the IT Partner monitoring system so IT Partner engineers can perform recurring monitoring.

What are IT Partner’s responsibilities in this service?

IT Partner monitors user activity and security-tool signals to identify events that merit attention, using machine learning and behavioral analytics to help reduce false positives and alert fatigue. IT Partner also prioritizes and investigates important alerts, passes real security incidents to the customer, assesses attacks and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation.

What are the customer’s responsibilities during the service?

The customer connects to the IT Partner monitoring system, maintains the Microsoft 365 and Microsoft Entra licensing that produces the risk signals, provides the required delegated access and consents, identifies contacts for incident notification and escalation, reviews escalated incidents, and authorizes remediation actions that fall outside the pre-approved scope.

What happens when IT Partner finds a real security incident?

When IT Partner identifies a real security incident, the incident is passed to the customer. IT Partner also assesses the attack and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation as part of the stated service deliverables.

Will IT Partner provide reporting or documentation?

Yes, the service includes communication of risk and performance data to the customer, as well as finalized auditing and documentation. The information can include which users are at risk, which risks were remediated or dismissed, detection details, history of risky sign-ins, and risk history.

Does the service require downtime or disrupt Microsoft 365 users?

The provided scope does not specify any planned downtime or user disruption for this monitoring service. Because the service is based on monitoring a Microsoft 365 tenant and connecting to the IT Partner monitoring system, any operational impact should be confirmed with IT Partner during onboarding.

Are remediation actions included in the service?

The service includes response to suspicious attempts, assessment of attacks and mitigation steps, forensic data gathering, auditing, documentation, and handing real security incidents to the customer. Full hands-on remediation and containment actions are scoped separately — remediation responsibilities and authorization are confirmed with IT Partner at onboarding.

What is not included in Risky Users and Risky Sign-ins Monitoring?

24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and Microsoft support escalation channels when separately purchased and stated in the customer agreement. Prospective buyers should also confirm with IT Partner whether activities such as broader incident response, configuration changes, remediation execution, or non-Microsoft 365 monitoring are included or handled separately.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

Free, Clients Only
30 days
Book a meeting