Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Product: Microsoft 365
Summary: Learn how to use the redesigned Huntress Managed ITDR dashboard to investigate identity activity, review risk and incident context, search identity events, and take action from one place.
In this Article
Overview
How to Access the Dashboard
Dashboard Overview
Rapid Identity Triage
Failed Login Characterization
Quick SIEM Search
Dashboard Transition
Overview
The redesigned Huntress Managed ITDR dashboard is now generally available to all ITDR subscribers.
The dashboard brings identity data, investigation context, and self-service capabilities into one place. Use it to review active risk, understand what Huntress is investigating, investigate identity activity, and take action when necessary.
How to Access the Dashboard
Log in to Huntress and go to ITDR > ITDR Dashboard.
Dashboard Overview
The redesigned dashboard provides a central view of the ITDR environment, including:
Active incidents requiring attention
Identities and events monitored by Huntress
Recent investigations
Sign-in activity and locations
Integration health
Coverage across Huntress ITDR capabilities
When Huntress detects malicious activity, the Huntress Security Operations Center (SOC) investigates and responds. When you need to answer a question about identity activity, the dashboard provides a faster path to the supporting evidence.
Rapid Identity Triage
Rapid Identity Triage helps you quickly investigate a user to determine whether an identity may be compromised.
Search for an identity by email address to view activity from the past 24 hours, current risk signals, and incident context. From the same view, you can review:
Recent sign-ins and locations
VPN or proxy usage
Browsers
Failed login activity
Additional activity context that can help determine whether behavior is expected or suspicious
An AI-assisted Quick Summary highlights important details without requiring you to manually piece together each event.
Additional actions include:
Expand the activity window to 48 hours or seven days
Export the activity timeline
Revoke active sessions
Disable the account
Failed Login Characterization
Failed Login Characterization adds context to failed authentication activity so you can better distinguish routine authentication noise from activity that may require investigation.
Review failed login activity across locations and identify activity associated with infrastructure, such as:
Residential proxies
VPNs
Tunnels
Datacenters
The dashboard also shows successful and failed sign-ins by location, along with activity associated with specific VPN, proxy, and datacenter providers.
Quick SIEM Search
Quick SIEM Search provides direct access to identity activity from the ITDR dashboard. Huntress ingests the Microsoft Entra Unified Audit Log and stores it in Huntress Managed Security Information and Event Management (SIEM) for up to one year at no additional cost for ITDR customers.
Search identity events by:
User
IP address
Operation
ES|QL query
The dashboard includes pre-populated searches for common investigation questions, including:
Failed login attempts
Failed MFA attempts
Conditional Access blocks
Global Admin role assignments
MFA changes
Events within a particular session
Use the full Huntress Managed SIEM experience when you need additional search and investigation capabilities.
Dashboard Transition
The redesigned dashboard is the default experience for Huntress Managed ITDR. The previous dashboard will be phased out over the next few weeks.