MicrosoftMicrosoft Entra

    Entra ID Protection

    Risk-based identity protection that detects and responds to compromised accounts.

    Microsoft Entra ID Protection uses machine learning and Microsoft’s vast signal to detect identity risk — risky sign-ins, compromised accounts, and leaked credentials — and automatically respond through risk-based conditional access. It turns identity risk into automated protection. Faltrox operates it as managed identity protection.

    Overview

    What Entra ID Protection is

    Compromised identities are behind a large share of breaches, and they are hard to spot — a valid credential used by an attacker looks legitimate. Microsoft Entra ID Protection detects that risk using machine learning across Microsoft’s trillions of signals, and responds automatically before the compromise spreads.

    It calculates real-time and offline risk for sign-ins and users — detecting anomalous sign-ins, impossible travel, leaked credentials, and known attack patterns — and feeds that risk into risk-based conditional access, which can require MFA, force a password reset, or block access automatically. It surfaces risky users and sign-ins for investigation and integrates with the wider Entra and Defender estate. Faltrox operates it as managed identity protection — tuning risk policy and responding to identity risk.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Risky Sign-Ins

    Detects anomalous, impossible-travel, and known-attack-pattern sign-ins.

    02

    Leaked Credentials

    Detects credentials found leaked or compromised.

    03

    Compromised Accounts

    Surfaces users at risk of compromise for investigation.

    04

    ML Risk Scoring

    Machine learning scores identity risk across Microsoft’s vast signal.

    05

    Risk-Based Response

    Risk-based conditional access requires MFA, resets, or blocks automatically.

    06

    Entra & Defender

    Integrates with Entra ID and Defender for correlated protection.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Detect

      Machine learning scores real-time and offline identity risk across Microsoft’s vast signal.

    2. 02

      Assess

      It surfaces risky sign-ins, risky users, and leaked credentials with a risk level.

    3. 03

      Respond

      Risk-based conditional access requires MFA, forces a password reset, or blocks access automatically.

    4. 04

      Investigate

      Risky users and sign-ins are surfaced for analyst investigation and remediation.

    5. 05

      Operate

      Faltrox tunes the risk policy and responds to identity risk as managed identity protection.

    Capabilities

    Key capabilities

    ML Risk Detection

    Machine learning detects identity risk across Microsoft’s trillions of signals.

    Risky Sign-In Detection

    Detects anomalous, impossible-travel, and known-attack-pattern sign-ins.

    Leaked-Credential Detection

    Detects credentials found leaked or compromised on the dark web.

    Risk-Based Conditional Access

    Automatically requires MFA, forces password reset, or blocks based on risk.

    Risky-User Surfacing

    Surfaces risky users and sign-ins for investigation and remediation.

    Automated Response

    Turns identity risk into automated protection before compromise spreads.

    Entra & Defender Integration

    Integrates with Entra ID and Defender XDR for correlated protection.

    Reporting & Investigation

    Rich reporting and investigation of identity risk over time.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Entra ID Protection for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does Entra ID Protection detect?

    Identity risk — risky sign-ins (anomalous, impossible travel, known attack patterns), leaked credentials, and users at risk of compromise — using machine learning across Microsoft’s trillions of signals. It spots the valid-but-compromised credentials that look legitimate to other tools.

    02How does it respond automatically?

    Through risk-based conditional access — when risk is detected, it can automatically require MFA, force a password reset, or block access, stopping a compromise before it spreads without waiting on a human. Faltrox tunes those risk policies.

    03How is it different from Defender for Identity?

    Entra ID Protection focuses on cloud identity risk and automated risk-based response (risky sign-ins, leaked credentials); Defender for Identity focuses on detecting identity attacks in Active Directory and Entra ID (credential theft, lateral movement). They are complementary layers of identity security.

    04Does it use Microsoft’s threat signal?

    Yes — its machine-learning risk detection draws on Microsoft’s vast global signal (trillions of signals a day), which is what lets it detect leaked credentials and attack patterns that a single organisation could not see.

    05How does Faltrox operate it?

    We tune the risk detection and risk-based conditional access policy, respond to and investigate identity risk, and correlate it across Entra and Defender — delivering managed identity protection that turns identity risk into automated defence.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us