Login Investigator
The Login Investigator agent validates whether a user’s recent sign-ins are legitimate by orchestrating Microsoft Entra and Defender skills. It builds a 30-day (configurable) baseline, evaluates the latest relevant interactive sign-in, checks IP reputation, device management status, user risk, Conditional Access outcomes, and related Defender XDR incidents—then produces a concise Markdown report with evidence, sources, and prioritized actions.
UPN, LookbackDays (default 30), IncidentLookbackDays (default 30), Strictness, OutputLanguage.
Fetch user profile → Retrieve interactive sign-ins → Build baseline → Select latest relevant sign-in → Check IP reputation → Verify device managed status → Check risky user state → Evaluate Conditional Access outcomes → List related Defender incidents → Compare against baseline → Produce risk assessment and report.
Markdown report with Summary, Checklist (Evidence + Source), Evidence section, Related Incidents table, and Recommended Actions.
Enable Login Investigator in the Security Copilot Agents gallery.
Consent to required plugins: M365 (Defender XDR), Entra, ThreatIntelligence.DTI, Intune.
Confirm required skillsets in the extension: M365, Entra, Intune, ThreatIntelligence.DTI, and Local Login Investigator.
On-demand: provide a UPN to analyze a specific user login.
Optional parameters: LookbackDays (default 30), Strictness (default balanced), Language (default en-US), Incident Look Back Days (default 30).
Want to validate a suspicious login in minutes?
Contact us to activate Login Investigator and standardize evidence-based sign-in validation across Entra, Intune, Defender XDR, and Threat Intelligence.
Evidence-driven. Baseline-aware. Designed to reduce false positives and accelerate triage.