Entra ID Protection
Risk-based identity protection that detects and responds to compromised accounts.
Microsoft Entra ID Protection uses machine learning and Microsoft’s vast signal to detect identity risk — risky sign-ins, compromised accounts, and leaked credentials — and automatically respond through risk-based conditional access. It turns identity risk into automated protection. Faltrox operates it as managed identity protection.
Overview
What Entra ID Protection is
Compromised identities are behind a large share of breaches, and they are hard to spot — a valid credential used by an attacker looks legitimate. Microsoft Entra ID Protection detects that risk using machine learning across Microsoft’s trillions of signals, and responds automatically before the compromise spreads.
It calculates real-time and offline risk for sign-ins and users — detecting anomalous sign-ins, impossible travel, leaked credentials, and known attack patterns — and feeds that risk into risk-based conditional access, which can require MFA, force a password reset, or block access automatically. It surfaces risky users and sign-ins for investigation and integrates with the wider Entra and Defender estate. Faltrox operates it as managed identity protection — tuning risk policy and responding to identity risk.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Risky Sign-Ins
Detects anomalous, impossible-travel, and known-attack-pattern sign-ins.
Leaked Credentials
Detects credentials found leaked or compromised.
Compromised Accounts
Surfaces users at risk of compromise for investigation.
ML Risk Scoring
Machine learning scores identity risk across Microsoft’s vast signal.
Risk-Based Response
Risk-based conditional access requires MFA, resets, or blocks automatically.
Entra & Defender
Integrates with Entra ID and Defender for correlated protection.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Detect
Machine learning scores real-time and offline identity risk across Microsoft’s vast signal.
- 02
Assess
It surfaces risky sign-ins, risky users, and leaked credentials with a risk level.
- 03
Respond
Risk-based conditional access requires MFA, forces a password reset, or blocks access automatically.
- 04
Investigate
Risky users and sign-ins are surfaced for analyst investigation and remediation.
- 05
Operate
Faltrox tunes the risk policy and responds to identity risk as managed identity protection.
Capabilities
Key capabilities
ML Risk Detection
Machine learning detects identity risk across Microsoft’s trillions of signals.
Risky Sign-In Detection
Detects anomalous, impossible-travel, and known-attack-pattern sign-ins.
Leaked-Credential Detection
Detects credentials found leaked or compromised on the dark web.
Risk-Based Conditional Access
Automatically requires MFA, forces password reset, or blocks based on risk.
Risky-User Surfacing
Surfaces risky users and sign-ins for investigation and remediation.
Automated Response
Turns identity risk into automated protection before compromise spreads.
Entra & Defender Integration
Integrates with Entra ID and Defender XDR for correlated protection.
Reporting & Investigation
Rich reporting and investigation of identity risk over time.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Entra ID Protection for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does Entra ID Protection detect?
Identity risk — risky sign-ins (anomalous, impossible travel, known attack patterns), leaked credentials, and users at risk of compromise — using machine learning across Microsoft’s trillions of signals. It spots the valid-but-compromised credentials that look legitimate to other tools.
02How does it respond automatically?
Through risk-based conditional access — when risk is detected, it can automatically require MFA, force a password reset, or block access, stopping a compromise before it spreads without waiting on a human. Faltrox tunes those risk policies.
03How is it different from Defender for Identity?
Entra ID Protection focuses on cloud identity risk and automated risk-based response (risky sign-ins, leaked credentials); Defender for Identity focuses on detecting identity attacks in Active Directory and Entra ID (credential theft, lateral movement). They are complementary layers of identity security.
04Does it use Microsoft’s threat signal?
Yes — its machine-learning risk detection draws on Microsoft’s vast global signal (trillions of signals a day), which is what lets it detect leaked credentials and attack patterns that a single organisation could not see.
05How does Faltrox operate it?
We tune the risk detection and risk-based conditional access policy, respond to and investigate identity risk, and correlate it across Entra and Defender — delivering managed identity protection that turns identity risk into automated defence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us