Solutions · Account takeover alerts
Know when someone else is in a client’s account, and contain it.
Each client tenant’s sign-in and audit logs are read about every 15 minutes. A likely takeover goes to email, Teams or Slack, with the sign-ins behind it and a way to contain the account in one approved step.
30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.


- Impossible travel, explained in plain words
- How serious it is
Why this is hard today
Takeovers show up first in the sign-in and audit logs of a client’s own tenant: a sign-in from two countries an hour apart, MFA prompts declined, a new admin. Watching those logs in every tenant by hand is not something a small team can do.
How ConfigCheckup solves it
From the tenant’s own logs
22 kinds of detection, such as impossible travel, password spraying, MFA prompts declined, an admin role given and an app given a risky consent.Only what matters
Routine changes and ConfigCheckup’s own changes are left out. Choose which detections alert, and their thresholds.The evidence with the alert
The sign-ins and changes behind every alert: who, when, from where and with which app.Contained in one approved step
Sign-in blocked, every session revoked and inbox rules that send mail outside turned off, as one change you approve.
Connect
The read-only consent already reads the sign-in and audit logs; nothing else to install.
Get the alert
By email, in Teams or in Slack, with the sign-ins or changes behind it.
Contain it
Contain the account from the alert as one approved change, or let high-confidence takeovers be contained automatically under a policy you approve.
Containment is approved like every change
The approvals panel every change goes through, containment included: nothing runs until it is approved, and every decision is in the audit log. Demo workspace.


- Nothing runs until it is approved
- Every decision is recorded in the audit log
Check it yourself
- Every alert shows the sign-ins or audit records behind it, so you can check it in the tenant.
- Containment is a change like any other: a dry run, approval, an audit record and a way back, except the revoked sessions, which cannot be restored. Check it: Containment is a change like any other: a dry run, approval, an audit record and a way back, except the revoked sessions, which cannot be restored.
- The sign-in log is read and discarded; only the records behind an alert are kept. Check it: The sign-in log is read and discarded; only the records behind an alert are kept.
What it can’t see
Said plainly, so you know what you are buying.
- It is not a 24/7 security operations centre: alerts go to you, and nobody watches them for you.
- Sign-in detections need Entra ID P1 in the client’s tenant; the audit-log detections do not.
- Logs are read about every 15 minutes, so an alert can follow a sign-in by that long.
It reads settings and activity records, never content, with permissions your client’s admin grants. Every permission and role, and why
Questions
- Does it read the user’s mail to spot a takeover?
- No. It reads sign-in and audit records, never content. Inbox rules are read as rules: where they send mail, not what the mail says.
- Can it contain an account without me?
- Only if you switch on automatic containment for that client, and only for high-confidence takeovers such as impossible travel or MFA fatigue. Emergency and service accounts can be left out, and every containment is reported and can be rolled back.
Plans: Alerts on every plan; containment, approved or automatic with Automate and above.
What each plan includesSee it on your own tenants.
The findings and figures come from your client’s own tenant, not from averages.
30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.