What this service offers
This service extends monitoring into SaaS identity providers to catch impossible travel, MFA abuse, rogue admins, and dangerous mailbox rules.
It covers the SaaS and identity layer for hybrid workforces.
- Impossible-travel and suspicious login pattern detection
- MFA fatigue / bypass style risk signals
- Rogue admin and privilege escalation alerts
- Dangerous inbox forwarding rule flags
- Unified view alongside on-prem alerts in the portal