Microsoft icon

Microsoft Entra ID Protection

Identity threat detection & risky sign-in alerts

Microsoft Entra ID Protection (formerly Azure AD Identity Protection) is a cloud identity security service that detects and responds to identity-based risks such as leaked credentials, impossible travel, and anomalous sign-in behavior. It works alongside Entra ID to enforce risk-based conditional access policies that automatically challenge or block suspicious logins.

How it works

Direct API integration (azure_identity_protection) pulling identity risk signals from Entra.

Data ingested

Risky sign-ins, identity risk events, conditional access signals

Frequently asked questions

What security services work with Microsoft Entra ID Protection, and how do I connect one?

You connect Expel to Microsoft Entra ID Protection by authorizing Workbench to ingest its alerts, including impossible travel detections, through Expel’s onboarding process. Expel also requests console access to pull vendor alert activity timelines. Expel’s detection engine and analysts are then able to correlate the identity data with session and login behavior to identify post-exploitation activity and trigger auto-remediations like disabling accounts or resetting credentials.

What does Expel's integration with Entra ID Protection actually do with its alerts?

Expel ingests Entra ID Protection’s impossible travel alerts into Workbench and correlates them with Expel’s own SharePoint access anomaly detections from the same user session. That correlation raises confidence on identity attacks that would otherwise look like isolated, low-priority events, and it can trigger automatic remediation, including password expiration and session token revocation.

How is Expel different from relying only on Entra ID Protection's native alerting?

Expel correlates Entra ID Protection’s impossible travel alerts with its own SharePoint access anomaly detections in the same user session, something Entra ID Protection can’t do on its own. Native alerting treats those signals as isolated, lower-confidence events. Expel’s correlation raises confidence and can trigger automatic remediation, including revoking a compromised account’s session tokens.

What are the top features of Expel's Entra ID Protection integration?

The most specific feature of Expel’s Entra ID Protection integration is session-level correlation: Expel matches Entra ID Protection’s impossible travel alerts against its own SharePoint access anomaly detections from the same session. Expel also automatically expires compromised passwords, revokes active session tokens, and can disable a compromised account entirely through API-based remediation.

Can Expel automatically respond to compromised accounts flagged by Entra ID Protection?

Expel can automatically respond to compromised accounts flagged by Entra ID Protection by expiring the user’s password and revoking all active session tokens through an API call. Expel can also disable the compromised account entirely when warranted. These actions follow Expel’s correlation of Entra ID Protection alerts with SharePoint access anomalies in Workbench.