RSA Advisor for Admin Threats
RSA Security · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
The RSA Advisor for Admin
Threats conducts a comprehensive analysis of administrative activity within an
Show the rest of the publisher’s description (14 more lines)
ID Plus tenant through administrator logs that are stored within the Sentinel
Datalake. This agent is designed to identify and surface potentially suspicious
activity that could indicate the compromise of an administrator account and/or
a potential insider threat. Utilizing this advisor, security administrators and
analysts can save time, as it automates the process of searching through logs
and correlating events using natural language prompts, resulting in quicker and
more accurate conclusions.
Estimated SCU consumption per execution:
- Small environments: ~0.2 SCUs
(e.g., lower administrative activity and limited event volume ~100 Events )
- Medium environments: ~0.3 SCUs
(e.g., moderate administrative activity and event volume ~200 Events)
- Large environments: ~0.4 SCUs
(e.g., higher administrative activity and larger event volumes ~500 Events)
Preview
5 imagesAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMP AuthorizedConfirmed95%, domain-verifiedRSA® ID Plus for Government is FedRAMP Authorized at Moderate impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Sources
Publisher resources
2 linksEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






