Security Posture
84/100
Overall security score
● Stable
↓ 2 pts vs last week
Critical Business Risks
3
Immediate attention required
▲ High severity
Identity · Data · Endpoint
Users at Risk
4
Potential account compromise
Review required
2 critical · 2 high priority
Managed Devices
—
Defender + Azure VMs
DeviceInfo + ARM
Onboarded endpoints
Active Risk Intelligence
Active Risks Impacting Business
3 Critical
Risk Trend — 30 Days
Alerts
Incidents
- Loading live 30-day trend…
Accounts, Geography & Compliance
Accounts Requiring Immediate Review
4 Flagged
Geographic Risk Indicators
Charlotte NC — baseline
Bermuda — anomaly detected
Compliance Posture
Medium Risk
Key insight: Auto-label enforcement remains the largest compliance gap.
Two policies must be promoted from Simulation to Enforce before the BMA audit.
Generated — —
3
Critical Investigations
Immediate attention
4
High Priority
Needs ownership
4
Risky Users
Entra + Sentinel
27
Managed Assets
VMs · laptops · servers
Active Investigations
Grouped Live Signals
By entity
Network + Storage Correlation
Last 24h
Tunnel Stability Timeline — Harmony disconnects vs auth drift
Authentication Drift
Kerberos
78%
NTLM
22%
Recommended Next Move
NTLM usage is increasing on mrecorporatefiles. Investigate whether tunnel instability or device sign-in flow is driving fallback behavior before next migration step.
Incident Timeline
Identity → Network → Endpoint → Storage
Alert Stream
10
Devices Online
—
Active <1h
Open Incidents
3
Sentinel + Defender
Identity Risks
4
Entra risky accounts
Managed Devices
—
Defender + Azure VMs
Device Inventory by Type
Alert Volume by Source (24h)
Sign-in Failures (24h)
—
SigninLogs
Affected Users
—
Unique accounts
Top Error Code
—
Loading…
Conditional Access
Active
Entra CA policies enforced
Top Error Codes — 24h
| Error Code | Reason | Count | Affected Users | Sample IP |
|---|
Users by Failure Count — 24h
| User | Failures | Error Codes | IPs | Last Failure |
|---|
Sign-in Anomalies
| User | IP | Location | Result | Time |
|---|
Risky Users — Entra ID Protection
| User | Risk | Detail | Last Seen | Action |
|---|
Active Tunnels
22
Harmony SASE sessions
Disconnects (24h)
23
8 from 1 device
Blocked Connections
47
Policy enforced
VNet Health
3/3
All reachable
VNet Traffic — 24h
Harmony Tunnel Status
| Device | User | Location | Duration | Status |
|---|
Tunnel Disconnection Events — 24h per Device
Harmony SASE — Active Device Locations
Charlotte NC (14)
Hamilton BM (3)
Anomaly detected
Source: Perimeter81_CL · Fields: device_hostname_s · agent_ip_s · user_email_s · eventName_s
Laptops
—
Intune managed
Azure VMs
—
All VMs in tenant
Devices Not in Compliance
—
Requires remediation
Shelf Inventory
—
Total across locations
Intune Compliance Status
Live from Intune
Devices not in compliance
—
Connector errors
—
Service health
—
Configuration policies with errors or conflict
—
Client app install failures
—
Account status
—
Shelf Inventory by Location
Autopilot group tags · Live from Intune
Charlotte
Wiped
—
New
—
Stale
—
Pending Reimage
—
Bermuda
Wiped
—
New
—
Stale
—
Pending Reimage
—
All Managed Assets
27 devices
| # | Device | Type | User | Compliance | Location | IP |
|---|
Select a device
to see context
to see context
Open DLP Findings
0
Unresolved
Policies Active
3
Enforcing auto-label
Labels Applied (7d)
470
SharePoint / OneDrive
Labels Removed (7d)
16
2 without justification
Auto-Label Policy Status
Sensitivity Label Activity (30d)
Sensitivity Label Usage (applied, last 30 days)
Loading label usage…
Labels Removed
—
last 30 days
Labels Downgraded
—
last 30 days
Protection Change Audit Trail (30d)Every label removal or downgrade, with the recorded business justification
| Time | User | Action | Label change | Item | Justification |
|---|---|---|---|---|---|
| Loading audit trail… | |||||
SMB Conn Failures (24h)
—
DeviceNetworkEvents
Public Route Leakage
—
Should be 0 (Private only)
P Drive Lockouts (24h)
—
AADDomainServicesAccountLogon
Wrong Passwords (24h)
—
AADDS 0xC000006A
NetApp P Drive — AADDS Authentication
Account Lockouts + Wrong Password Events — 24h
—
| Time | Account | Error Type | Error Code |
|---|
Azure Files + NetApp — SMB Connection Failures
Connection Failures — User + Device + Route
—
| Time | Device | User | Route | Remote URL | Remote IP |
|---|
Entra Kerberos Migration Status
File Share Access Log
| Device | User | Endpoint | Type | Conns | Auth | Last Seen |
|---|
Critical
2
Sentinel incidents
High
3
Review today
Medium
2
Monitor
Resolved (7d)
14
Closed this week
All Incidents — Sentinel + Defender
| ID | Title | Source | Severity | Entity | Created | Status | MITRE |
|---|
Alerts
7