Risky Users and Risky Sign-Ins Monitoring — Microsoft Entra ID
Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.
What this engagement is
This service helps customers monitor risky users and risky sign-ins in a Microsoft 365 environment. IT Partner engineers use Microsoft tools and security signals to identify users at risk, risky sign-in history, detection details, risk history, and cases where risk was remediated or dismissed.
Success criteria
What you receive
How the work unfolds
The customer connects to IT Partner monitoring system.
IT Partner engineers manage recurring monitoring of risky users and risky sign-ins.
Prerequisites
Who does what
IT Partner
- IT Partner monitors user activity, and signals from security tools to identify events that merit attention and leverage machine learning and behavioral analytics to reduce false positives and alert fatigue, discover hard-to-detect complex events like lateral movement, insider threats and data exfiltration.
- IT Partner prioritizes, selects the most important alerts, and investigates them further. Real security incidents are passed to the customer.
- IT Partner staff assesses the attack and mitigation steps, gathers additional forensic data and finalizes auditing and documentation.
Your team
- The customer connects to IT Partner monitoring system.
- Maintain the Microsoft 365 and Microsoft Entra licensing required for the risk signals, audit logs, and identity protection features used by the monitoring service.
- Provide or approve the required delegated access, security-reader permissions, monitoring connector consent, and other tenant access needed for IT Partner engineers to perform the service.
- Identify customer security, IT, and business contacts for incident notification, escalation, and approval of any customer-side actions.
- Review escalated incidents, confirm business context, and authorize remediation actions such as password reset, MFA registration enforcement, account blocking, or conditional access changes when those actions are outside the pre-approved scope.
- Maintain accurate user, administrator, and service account ownership information so risky-user findings can be triaged correctly.
- Notify IT Partner about planned identity changes, migrations, administrator changes, known high-risk activities, or exceptions that may affect risk scoring or investigation context.
What's not included
Limitations & technical notes
Frequently asked questions
What is Risky Users and Risky Sign-ins Monitoring?
Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.
What does IT Partner monitor in this service?
IT Partner monitors risky users, risky sign-ins, user activity, and signals from Microsoft security tools in the customer’s Microsoft 365 environment. The monitoring includes information about users currently at risk, users whose risk was remediated or dismissed, detection details, risky sign-in history, and overall risk history.
How much does Risky Users and Risky Sign-ins Monitoring cost?
The service is listed as free of charge for IT Partner clients. There is no separate monitoring fee; confirm eligibility and onboarding steps with IT Partner before the service starts.
Is this a one-time assessment or an ongoing managed service?
Risky Users and Risky sign-ins monitoring is an ongoing managed service, not a one-time assessment. It runs on a recurring basis — free of charge for IT Partner clients — so new risky users, risky sign-ins, and risk history are monitored over time.
What prerequisites are required before starting the service?
The stated prerequisite is that the customer must have a Microsoft 365 tenant. The customer also needs to connect to the IT Partner monitoring system so IT Partner engineers can perform recurring monitoring.
What are IT Partner’s responsibilities in this service?
IT Partner monitors user activity and security-tool signals to identify events that merit attention, using machine learning and behavioral analytics to help reduce false positives and alert fatigue. IT Partner also prioritizes and investigates important alerts, passes real security incidents to the customer, assesses attacks and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation.
What are the customer’s responsibilities during the service?
The customer connects to the IT Partner monitoring system, maintains the Microsoft 365 and Microsoft Entra licensing that produces the risk signals, provides the required delegated access and consents, identifies contacts for incident notification and escalation, reviews escalated incidents, and authorizes remediation actions that fall outside the pre-approved scope.
What happens when IT Partner finds a real security incident?
When IT Partner identifies a real security incident, the incident is passed to the customer. IT Partner also assesses the attack and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation as part of the stated service deliverables.
Will IT Partner provide reporting or documentation?
Yes, the service includes communication of risk and performance data to the customer, as well as finalized auditing and documentation. The information can include which users are at risk, which risks were remediated or dismissed, detection details, history of risky sign-ins, and risk history.
Does the service require downtime or disrupt Microsoft 365 users?
The provided scope does not specify any planned downtime or user disruption for this monitoring service. Because the service is based on monitoring a Microsoft 365 tenant and connecting to the IT Partner monitoring system, any operational impact should be confirmed with IT Partner during onboarding.
Are remediation actions included in the service?
The service includes response to suspicious attempts, assessment of attacks and mitigation steps, forensic data gathering, auditing, documentation, and handing real security incidents to the customer. Full hands-on remediation and containment actions are scoped separately — remediation responsibilities and authorization are confirmed with IT Partner at onboarding.
What is not included in Risky Users and Risky Sign-ins Monitoring?
24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and Microsoft support escalation channels when separately purchased and stated in the customer agreement. Prospective buyers should also confirm with IT Partner whether activities such as broader incident response, configuration changes, remediation execution, or non-Microsoft 365 monitoring are included or handled separately.