02.1Discover
IT never approved it. Sixty-three people use it.
Sign-in logs and OAuth grants name the unapproved applications, including the AI tools that asked to read mail. You install nothing.
- No laptop agent
- OAuth grants, sign-in logs and email metadata
- 33 of the 181 applications are flagged as AI
All of Discover
02.2Detect
Nobody connected the five alerts. We did.
A session hijack at 02:14, an impossible-travel sign-in, an MFA anomaly, an OAuth consent and a forwarding rule, inside thirty minutes. They arrive as one incident.
- Correlated on the identity and on the source address
- The mapped technique sits on every step
- Held in the order they happened
All of Detect
02.3Govern
Denied in the review means denied in the directory.
Reviewers see last sign-in and usage frequency before deciding. Once the review closes, each denial is revoked in Entra.
- Last sign-in and usage on every row
- A denial calls the directory itself
- A failed revoke is reported per account
All of Govern
02.4Posture
One account reaches four applications, and nobody mapped how.
It counts direct grants, group membership, nested groups and roles. Findings rank by reach, and the one worth fixing first is the one that gets furthest.
- Direct grants, groups, nested groups and roles
- Ranked by what the account can reach
- Every open finding re-confirmed every six hours
All of Posture