Login Investigator Agent
adaQuest · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
Login Investigator is a Security Copilot agent designed to analyze and contextualize user authentication activity across Microsoft Entra ID.
The agent provides security teams with a clear view of how identities are accessing corporate resources by analyzing sign-in activity within a defined lookback window (default 7 days). By consolidating authentication telemetry, Login Investigator helps analysts quickly understand where users are logging in from, which devices are used, and how authentication protections such as MFA and Conditional Access are applied.
Show the rest of the publisher’s description (15 more lines)
Login Investigator automatically correlates identity signals including successful and failed logins, geographic access patterns, IP intelligence, and device posture. The agent also enriches authentication sources using Microsoft Defender Threat Intelligence (MDTI) when available to identify potentially malicious infrastructure involved in login activity.
The resulting investigation report highlights authentication anomalies, suspicious access patterns, and identity risk indicators, allowing SOC analysts and security administrators to rapidly determine whether a user account is behaving normally or potentially compromised.
Login Investigator is designed to reduce the manual effort required to investigate authentication events by consolidating identity telemetry, security context, and threat intelligence into a single structured investigation output.
Key capabilities
- Analysis of user sign-in activity within a configurable investigation window (default 7 days)
- Visibility into successful and failed login sources, including regions and IP addresses
- IP reputation enrichment using Microsoft Defender Threat Intelligence (MDTI) when available
- Identification of authentication anomalies and suspicious login patterns
- Device context analysis including Intune device compliance when available
- Authentication security insights including MFA usage and Conditional Access enforcement
- Structured investigation reports designed for SOC analysts and security administrators
Security Copilot Units (SCU) consumption
Login Investigator is designed with efficient and predictable SCU consumption while performing identity investigation and enrichment workflows.
- Estimated SCU consumption per execution is ~5 SCU
Login Investigator applies scoped data retrieval, correlation-first analysis, and targeted enrichment queries to optimize execution efficiency while maintaining high-value identity investigation insights across environments of different sizes.
Preview
4 imagesAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
1 listedSources
Publisher resources
3 linksEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.





