Mondra · Security OperationsOverview
--:--:--UTC --:--
⚠RB-05 Scenario ARisky users

Needs action

–

Live activity

–
7 days · newest first

Threat origins

WAF blocks · 24h

Compromise watch

Incidents created

14 days
HighMedium and below

Platform health

–
detection pipeline · alerting · data feeds

Alert queue

–

PIM activity

–

Risky users & detections

Entra ID Protection

Failed sign-ins

interactive · 7 days · UTC hour

Sign-in countries

–

Standing privileged assignments

–
permanent · not via PIM

Directory changes

–
CA · apps · credentials · consent

Blocked requests by rule

hourly · last 24h · local time

Spike detection

vs 7-day hourly median

Block sources

Top countries

24h

Top source IPs

–
24h · AbuseIPDB, same call as the enrichment playbook

Data feeds

–
last record · cadence · ingestion per hour, 24h

Playbooks

–
Logic Apps · runs per day, 7 days

Billable ingestion

GB per day · 30 days · top tables

Sentinel workspace cost

–
workspace resource group · actual · daily
Daily cost

Analytics rules

–
–

By severity

MTTA = created to first analyst action · MTTR split analyst vs automation

Top detections

Response actions

–

⚠

What will happen
    ◉
    Touch ID to confirmPlace your finger on Touch ID, or use your Mac password.