Back to the registry
Agent passport

Sign-in Investigator

water IT Security GmbH · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

IdentityEntraSign-in
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 8 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Sign-In Investigator is an interactive Security Copilot agent that helps SOC and identity teams reduce the time and effort required to investigate suspicious user sign-ins. Instead of manually pivoting across Entra ID, Defender XDR, audit logs, email and URL telemetry, and threat intelligence, analysts receive a structured, evidence-based report with risk classification and containment guidance.

Customer benefits

Show the rest of the publisher’s description (61 more lines)
  • Faster triage: combines Microsoft security signals into one workflow.
  • Consistent decisions: applies a repeatable, evidence-based risk rubric.
  • Transparent findings: explains why a sign-in is classified as low, medium, or high risk.
  • Actionable guidance: recommends containment and follow-up actions tied to observed users, IPs, locations, authentication patterns, and related telemetry.

How Sign-In Investigator works

  • Resolving a Microsoft Defender incident and extracting affected users, IP addresses, and flagged URLs.
  • Retrieving Entra ID sign-in logs and calculating anomaly indicators including new locations, MFA status, conditional access outcomes, device posture, legacy authentication use, and sign-in error interpretation.
  • Detecting VPN, hosting provider, or proxy usage from sign-in metadata.
  • Pulling identity context including assigned roles, account status, Entra risk level, password and MFA history, and recent administrative activity.
  • Enriching suspect IP addresses with Microsoft Defender Threat Intelligence reputation data.
  • Inspecting email events and URL click telemetry related to the incident.
  • Classifying findings using an evidence-based risk rubric.
  • Compiling evidence tables and recommending containment actions referencing the identified users, IPs, and patterns.

Inputs

A Microsoft Defender Incident ID or user principal name (UPN). The default investigation window is 7 days but can be extended, for example “past 30 days.”

Outputs

A structured Markdown report covering incident summary, recommended actions, authentication analysis, VPN assessment, identity details, IP reputation, URL activity, email findings, and behavioral patterns.

Required Microsoft products

  • Microsoft

Entra ID P2 (sign-in log retention and risk signals)

  • Microsoft

Defender for Office 365 Plan 2 (email and URL click telemetry)

  • Microsoft

Defender Threat Intelligence (IP reputation enrichment)

Optional Microsoft products

  • Microsoft

Defender for Identity, or Microsoft Sentinel UEBA (expanded identity-role and

manager-attribution data)

Required role-based access control (RBAC)

Security Reader is the minimum role for read-only investigation. Security Operator or higher is required for containment actions such as password reset, session revocation, or account lock.

Estimated SCU consumption

0.3 to 0.6

Security Compute Units per incident investigation. Actual consumption

varies with the number of suspect IP addresses, the size of the user's

recent sign-in history, and whether email or URL inspection returns

results.

Use cases

  • SOC tier-1 and tier-2 analysts triaging Entra ID and Defender identity incidents
  • Identity administrators auditing suspicious account activity
  • Threat intelligence teams enriching IOCs with Microsoft DTI data
  • Executive incident review summaries

Limitations

  • Impossible-travel detection relies on geo-IP approximations
  • Token-reuse detection is not performed
  • Legacy authentication detection depends on tenant logging and licensing
  • Recommendations do not perform automated remediation
  • Sign-in retention depends on Entra ID licensing

Privacy and data handling

The agent reads

telemetry from the customer's own Microsoft Defender and Entra ID

tenants. No customer data is sent outside the customer's Microsoft

tenant boundary. The agent does not call any third-party APIs and does

not require any external credentials.

About the publisher

Published by

water IT Security GmbH, a German cybersecurity consultancy

specializing in Microsoft security platform engineering and incident

response operations. Support contact and full release notes are

available via the publisher product page linked below.

# Version 1.1.0

# - Initial release

Preview

5 images
Sign-in Investigator preview 1Sign-in Investigator preview 2Sign-in Investigator preview 3Sign-in Investigator preview 4Sign-in Investigator preview 5

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Plans and pricing as listed

1 listed
Free Plan
First month free, then $0.00/month
1-month subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

3 links
Download Product One-Pagercatalogartifact.azureedge.netSource
See Product One-Pager onlinewww.water-security.deSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.water-security.de/contact/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.