Login Investigator

Login Investigator

The Login Investigator agent validates whether a user’s recent sign-ins are legitimate by orchestrating Microsoft Entra and Defender skills. It builds a 30-day (configurable) baseline, evaluates the latest relevant interactive sign-in, checks IP reputation, device management status, user risk, Conditional Access outcomes, and related Defender XDR incidents—then produces a concise Markdown report with evidence, sources, and prioritized actions.

Customer benefits

  • Faster triage: single-run validation across Entra, ID Protection, Intune, XDR, and Threat Intelligence.
  • Lower false positives: per-user baseline clarifies normal IPs, regions, devices, and client apps.
  • Traceable decisions: standardized evidence with explicit tool sources for audit/tickets.
  • No Sentinel dependency: works fully with global skills (no KQL fallback).
  • Actionable outcomes: prioritized recommendations (e.g., MFA prompts, password reset, CA tuning).

Products in scope

  • Microsoft Defender XDR (MDE/MDI/MDO)
  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Threat Intelligence (DTI)

Functional design (high level)

Inputs

UPN, LookbackDays (default 30), IncidentLookbackDays (default 30), Strictness, OutputLanguage.

Core flow

Fetch user profile → Retrieve interactive sign-ins → Build baseline → Select latest relevant sign-in → Check IP reputation → Verify device managed status → Check risky user state → Evaluate Conditional Access outcomes → List related Defender incidents → Compare against baseline → Produce risk assessment and report.

Output

Markdown report with Summary, Checklist (Evidence + Source), Evidence section, Related Incidents table, and Recommended Actions.

Manual trigger
On-demand
Run inputs
UPN (required)
LookbackDays (default 30)
Strictness (default balanced)
OutputLanguage (default en-US)
IncidentLookbackDays (default 30)
Report generated
Markdown

Enablement & how to run

Customer onboarding

Enable Login Investigator in the Security Copilot Agents gallery.

Consent to required plugins: M365 (Defender XDR), Entra, ThreatIntelligence.DTI, Intune.

Confirm required skillsets in the extension: M365, Entra, Intune, ThreatIntelligence.DTI, and Local Login Investigator.

How to run

On-demand: provide a UPN to analyze a specific user login.

Optional parameters: LookbackDays (default 30), Strictness (default balanced), Language (default en-US), Incident Look Back Days (default 30).

Want to validate a suspicious login in minutes?
Contact us to activate Login Investigator and standardize evidence-based sign-in validation across Entra, Intune, Defender XDR, and Threat Intelligence. Evidence-driven. Baseline-aware. Designed to reduce false positives and accelerate triage.

Request contact