Entra ID
Entra ID
Hal reads identity activity from Microsoft Entra ID through Microsoft Graph, over read-only permissions. This is the feed behind most identity alerts, impossible travel, risky sign-ins, and MFA changes.
What’s collected:
- Interactive and non-interactive sign-in logs
- Risk detections from Entra ID Protection
- Directory audit events, role changes, app consents, MFA registrations
- The Conditional Access outcome on each sign-in
Polled every few minutes, retained 365 days.
Note
Prerequisite: sign-in logs and their Conditional Access outcomes
need Entra ID P1 (or higher), and directory audits need no premium license.
Risk detections need P1 for the basic kinds, and P2 for the premium kinds
and sign-in risk scores. See Audit Logging Prerequisites.
Connect it: issued alongside Microsoft 365 in Getting Started, the same read-only app registration covers both.
See what Hal surfaces on your own clients.
No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.
- 01You ask us your questions. No deck, no demo dataset.
- 02You sign a short evaluation agreement, and we stand up your own instance.
- 03You connect one tenant from your own admin console. Hal watches it for 14 days.
- 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.