IAM Supervisor Agent
Performanta · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
The IAM Supervisor Agent by Performanta functions as an autonomous identity security analyst, orchestrating the end-to-end investigation of compromised user accounts within your Microsoft Sentinel environment. By integrating directly with your specific Workspace and Tenant context, the agent automatically retrieves and filters "New" security incidents based on your defined severity preferences (e.g., High, Medium). It then initiates a comprehensive assessment of the target user's security posture, efficiently distinguishing between benign anomalies and genuine identity threats without manual intervention.
Beyond basic triage, the agent executes five concurrent investigation streams to build a holistic view of the user's behavior. It analyzes authentication logs for signs of compromised credentials (such as impossible travel or token theft), evaluates insider risk indicators like data exfiltration, and scrutinizes MFA logs for fatigue attacks or bypass attempts. If the user holds elevated privileges, the agent performs a specialized deep-dive into admin activities and configuration changes. Finally, it synthesizes all findings into a unified opinion, providing security teams with a validated assessment and a prioritized remediation plan.
Show the rest of the publisher’s description (9 more lines)
Inputs:
- Microsoft Sentinel Incidents (filtered by Status='New', Severity, and timeframe).
- Microsoft Entra ID (Azure AD) user, group, and service principal data.
- Identity Protection risk alerts, Sign-in logs, and Audit logs.
- Tenant-specific context (Workspace Name, Resource Group, Subscription ID).
Outputs:
- A comprehensive investigation report containing a unified verdict (Low, Medium, or High confidence of compromise).
- A consolidated summary of findings across compromised credentials, insider risk, and MFA integrity.
- A prioritized, bulleted list of actionable remediation steps (e.g., "Revoke active sessions", "Reset password").
Preview
2 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listedSources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.



