Risky Users and Risky sign-ins monitoring
Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.
What this engagement is
This service helps customers monitor risky users and risky sign-ins in a Microsoft 365 environment. IT Partner engineers use Microsoft tools and security signals to identify users at risk, risky sign-in history, detection details, risk history, and cases where risk was remediated or dismissed. The service is recurring and is listed as SKU ITPWW060SECOT, priced at $10.00 per seat, with Roman Sotnik as the manager.
Success criteria
What you receive
How the work unfolds
The customer connects to IT Partner monitoring system.
IT Partner engineers manage recurring monitoring of risky users and risky sign-ins.
Prerequisites
Who does what
IT Partner
- IT Partner monitors user activity, and signals from security tools to identify events that merit attention and leverage machine learning and behavioral analytics to reduce false positives and alert fatigue, discover hard-to-detect complex events like lateral movement, insider threats and data exfiltration.
- IT Partner prioritizes, selects the most important alerts, and investigates them further. Real security incidents are passed to the customer.
- IT Partner staff assesses the attack and mitigation steps, gathers additional forensic data and finalizes auditing and documentation.
Your team
- The customer connects to IT Partner monitoring system.
- Maintain the Microsoft 365 and Microsoft Entra licensing required for the risk signals, audit logs, and identity protection features used by the monitoring service.
- Provide or approve the required delegated access, security-reader permissions, monitoring connector consent, and other tenant access needed for IT Partner engineers to perform the service.
- Identify customer security, IT, and business contacts for incident notification, escalation, and approval of any customer-side actions.
- Review escalated incidents, confirm business context, and authorize remediation actions such as password reset, MFA registration enforcement, account blocking, or conditional access changes when those actions are outside the pre-approved scope.
- Maintain accurate user, administrator, and service account ownership information so risky-user findings can be triaged correctly.
- Notify IT Partner about planned identity changes, migrations, administrator changes, known high-risk activities, or exceptions that may affect risk scoring or investigation context.
What's not included
Limitations & technical notes
Frequently asked questions
What is Risky Users and Risky Sign-ins Monitoring?
Risky Users and Risky sign-ins monitoring is a recurring managed service for organizations with a Microsoft 365 tenant that need recurring monitoring of risky users and risky sign-ins. IT Partner monitors user activity and security-tool signals, prioritizes and investigates important alerts, passes real security incidents to the customer, and communicates risk and performance data so the customer stays aware of risks across the organization.
What does IT Partner monitor in this service?
IT Partner monitors risky users, risky sign-ins, user activity, and signals from Microsoft security tools in the customer’s Microsoft 365 environment. The monitoring includes information about users currently at risk, users whose risk was remediated or dismissed, detection details, risky sign-in history, and overall risk history.
What deliverables are included with Risky Users and Risky Sign-ins Monitoring?
The service includes recurring monitoring of risky users and risky sign-ins, prioritization and investigation of important alerts, response to suspicious attempts, and communication of risk and performance data to the customer. It also includes assessment of attacks and mitigation steps, additional forensic data gathering, finalized auditing and documentation, and passing real security incidents to the customer.
Is this a one-time assessment or an ongoing managed service?
Risky Users and Risky sign-ins monitoring is an ongoing managed service, not a one-time assessment. It is provided on a recurring basis with a regular monthly fee so that new risky users, risky sign-ins, and risk history can be monitored over time.
What is the price for Risky Users and Risky Sign-ins Monitoring?
The listed price for Risky Users and Risky sign-ins monitoring is $10.00 per seat. The service is listed as SKU ITPWW060SECOT and is provided as a recurring service with a regular monthly fee.
What prerequisites are required before starting the service?
The stated prerequisite is that the customer must have a Microsoft 365 tenant. The customer also needs to connect to the IT Partner monitoring system so IT Partner engineers can perform recurring monitoring.
What does the customer need to do to start the service?
The customer’s stated responsibility is to connect to the IT Partner monitoring system. After that connection is in place, IT Partner engineers manage the recurring monitoring of risky users and risky sign-ins.
What are IT Partner’s responsibilities in this service?
IT Partner monitors user activity and security-tool signals to identify events that merit attention, using machine learning and behavioral analytics to help reduce false positives and alert fatigue. IT Partner also prioritizes and investigates important alerts, passes real security incidents to the customer, assesses attacks and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation.
What are the customer’s responsibilities during the service?
The customer is responsible for connecting to the IT Partner monitoring system. The source scope does not list additional customer responsibilities, so any required approvals, access requirements, or internal response procedures should be confirmed with IT Partner before onboarding.
What happens when IT Partner finds a real security incident?
When IT Partner identifies a real security incident, the incident is passed to the customer. IT Partner also assesses the attack and mitigation steps, gathers additional forensic data, and finalizes auditing and documentation as part of the stated service deliverables.
Does this service include investigation of every alert?
The service includes monitoring alerts and selecting the most important ones for further investigation. IT Partner prioritizes alerts because the service is designed to focus attention on events that merit action and reduce false positives and alert fatigue.
How does the service help reduce alert fatigue?
IT Partner uses security-tool signals, machine learning, and behavioral analytics to help identify events that merit attention. This helps reduce false positives and alert fatigue while improving visibility into complex events such as lateral movement, insider threats, and data exfiltration.
What types of risks can this service help identify?
The service helps identify risky users, risky sign-ins, detection details, risk history, and cases where risk was remediated or dismissed. The stated scope also references hard-to-detect complex events such as lateral movement, insider threats, and data exfiltration.
Will IT Partner provide reporting or documentation?
Yes, the service includes communication of risk and performance data to the customer, as well as finalized auditing and documentation. The information can include which users are at risk, which risks were remediated or dismissed, detection details, history of risky sign-ins, and risk history.
Does the service require downtime or disrupt Microsoft 365 users?
The provided scope does not specify any planned downtime or user disruption for this monitoring service. Because the service is based on monitoring a Microsoft 365 tenant and connecting to the IT Partner monitoring system, any operational impact should be confirmed with IT Partner during onboarding.
How long does implementation take?
The source does not specify a fixed implementation timeline. The stated implementation plan has two milestones: the customer connects to the IT Partner monitoring system, and then IT Partner engineers perform recurring monitoring.
What happens after the initial setup is complete?
After the customer connects to the IT Partner monitoring system, IT Partner begins recurring monitoring of risky users and risky sign-ins. The service continues on an ongoing recurring basis, with IT Partner monitoring risks, investigating important alerts, passing real incidents to the customer, and communicating risk and performance data.
Are remediation actions included in the service?
The service includes response to suspicious attempts, assessment of attacks and mitigation steps, forensic data gathering, auditing, documentation, and passing real security incidents to the customer. The source does not specify a full hands-on remediation scope or guaranteed containment actions, so remediation responsibilities and authorization should be confirmed with IT Partner.
What is not included in Risky Users and Risky Sign-ins Monitoring?
24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement when separately purchased and stated in the customer agreement. Prospective buyers should also confirm with IT Partner whether activities such as broader incident response, configuration changes, remediation execution, or non-Microsoft 365 monitoring are included or handled separately.
Who manages the Risky Users and Risky sign-ins monitoring service?
The service information lists Roman Sotnik as the manager for Risky Users and Risky sign-ins monitoring. The service itself is delivered by IT Partner engineers who manage recurring monitoring and investigation activities.