A comprehensive set of improvements to the ITDR escalation system, giving partners more control over their escalation experience and expanding coverage to new threat categories.
Planned enhancements include:
  1. Automated Response Actions
    — Option to automatically revoke sessions or disable identities when an escalatable event is detected, stopping potential account takeover immediately.
  2. Device Compliance Filtering
    — Suppress escalations from Entra joined, managed, or compliant devices at the account and organization level, reducing noise from trusted corporate devices.
  3. Escalation Opt-Out
    — Option to disable Unexpected Login escalation generation entirely at the account and organization level for partners who manage their own security workflows.
  4. Per-Identity Notifications
    — Each unique identity that triggers an escalatable event generates a separate notification, ensuring real incidents aren't buried in grouped alerts.
  5. Enriched Notifications
    — Escalation emails include tenant name, identity details, source IP, device info, and a direct link to the portal for faster triage.
  6. New Rogue App Escalations
    — Configurable escalations for new Entra app registrations and AI tooling apps, providing visibility into OAuth consent grants and shadow AI adoption.
  7. Admin Role Escalations
    — Configurable escalations for privileged role assignments and new admin account creation. Know immediately when an identity is granted Global Administrator, Exchange Administrator, or other security-relevant roles.
  8. Mail Forwarding Escalations
    — Configurable escalations when a mailbox is set to forward email to a consumer email provider, a primary BEC persistence mechanism.