Security teams may need to assess suspicious activity across devices, networks, cloud environments, email and Microsoft 365 users. Separate alerts and limited context can make it harder to understand whether device or user activity needs action.
Threat-hunting & Action Center monitors these sources in real time and presents pre-computed risk scores, attack analysis and investigative views. Its Action Center provides scans, quarantine, endpoint isolation, user logout and session revocation actions, bringing investigation and response together.
The product supports investigation of malicious device activity through real-time risk scoring and device-level forensic analysis. Teams can use the Action Center to scan, quarantine or isolate affected endpoints.
For Microsoft 365 users, it tracks activity including unusual login locations, failed logins and unrecognised IP addresses. User-based response actions include logging out users and revoking sessions when suspicious activity requires containment.
Threat-hunting & Action Center is applicable to endpoints, networks, cloud environments, email and Microsoft 365 user activity. Its user monitoring brings together Login Anomaly Detection, Email Security and Ransomware Encryption Protection insights.
Risk scores, attack analysis and investigative views bring relevant threat context into one place.
Device-level forensics and risk scoring support investigation of suspicious endpoint activity.
Microsoft 365 activity monitoring highlights unusual sign-in behaviour and unrecognised IP addresses.
The Action Center makes scans, quarantine, isolation, logout and session revocation available from the investigation view.
Review malicious device activity using real-time risk scoring and device-level forensic analysis.
Investigate Microsoft 365 users with unusual locations, failed logins or unrecognised IP addresses.
Use the Action Center to scan, quarantine or isolate endpoints in response to suspicious activity.
Log out users and revoke sessions when user-based threats require an immediate response action.
Armstrong discusses the sources of security activity teams need to investigate, including estate and Microsoft 365 user activity. This helps establish whether Threat-hunting & Action Center's monitoring, investigation views and available response actions fit the organisation's requirements.