The signs TenantWard watches for
- Inbox rules that forward mail outside or hide messages
- Sign-ins from a country the person has never used, followed by a new sign-in method
- High-risk sign-ins flagged by Microsoft
- New admins and new app approvals
Your choice of response
Alert only, open an incident with a guided lockdown, or contain automatically: block sign-in, end every session and disable the attacker's rule. You set who must never be locked and a limit per hour. Global Administrators are never blocked automatically.
The compromised-account runbook then walks you through resetting the password and MFA, reviewing rules and app consents, checking what was sent and restoring access with one click.
Payment fraud controls
Nine controls aimed at fake invoices and payment-change fraud, from external email tagging to alerts that put the finance team first, plus a payment-change policy you can adopt.
Questions
- How fast does TenantWard detect a compromised account?
- With 24/7 monitoring on the Protect plan, TenantWard checks every 15 minutes.
See where your company stands
Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.