Microsoft Entra ID Protection (formerly Azure AD Identity Protection) is a cloud identity security service that detects and responds to identity-based risks such as leaked credentials, impossible travel, and anomalous sign-in behavior. It works alongside Entra ID to enforce risk-based conditional access policies that automatically challenge or block suspicious logins.
How it works
Direct API integration (azure_identity_protection) pulling identity risk signals from Entra.
Data ingested
Risky sign-ins, identity risk events, conditional access signals
Frequently asked questions
You connect Expel to Microsoft Entra ID Protection by authorizing Workbench to ingest its alerts, including impossible travel detections, through Expel’s onboarding process. Expel also requests console access to pull vendor alert activity timelines. Expel’s detection engine and analysts are then able to correlate the identity data with session and login behavior to identify post-exploitation activity and trigger auto-remediations like disabling accounts or resetting credentials.
Expel ingests Entra ID Protection’s impossible travel alerts into Workbench and correlates them with Expel’s own SharePoint access anomaly detections from the same user session. That correlation raises confidence on identity attacks that would otherwise look like isolated, low-priority events, and it can trigger automatic remediation, including password expiration and session token revocation.
Expel correlates Entra ID Protection’s impossible travel alerts with its own SharePoint access anomaly detections in the same user session, something Entra ID Protection can’t do on its own. Native alerting treats those signals as isolated, lower-confidence events. Expel’s correlation raises confidence and can trigger automatic remediation, including revoking a compromised account’s session tokens.
The most specific feature of Expel’s Entra ID Protection integration is session-level correlation: Expel matches Entra ID Protection’s impossible travel alerts against its own SharePoint access anomaly detections from the same session. Expel also automatically expires compromised passwords, revokes active session tokens, and can disable a compromised account entirely through API-based remediation.
Expel can automatically respond to compromised accounts flagged by Entra ID Protection by expiring the user’s password and revoking all active session tokens through an API call. Expel can also disable the compromised account entirely when warranted. These actions follow Expel’s correlation of Entra ID Protection alerts with SharePoint access anomalies in Workbench.
