Marlo
SECURITY OPERATIONS CENTER
Restricted to martellore.com accounts
Sentinel Defender Harmony SASE Purview ThreatLocker
Martello Re
LIVE
30
🛡
Security posture is stable with active concerns. No confirmed data breaches. Two identity-related risks and one data protection violation require immediate review. Increased VPN instability may impact user productivity. BMA audit readiness currently at 71% — two policies require enforcement before October 2026.
Security Posture
84/100
Overall security score
● Stable
↓ 2 pts vs last week
Critical Business Risks
3
Immediate attention required
▲ High severity
Identity · Data · Endpoint
Users at Risk
4
Potential account compromise
Review required
2 critical · 2 high priority
Managed Devices
Defender + Azure VMs
DeviceInfo + ARM
Onboarded endpoints
Active Risk Intelligence
Active Risks Impacting Business
3 Critical
Risk Trend — 30 Days
Alerts
Incidents
  • Loading live 30-day trend…
Accounts, Geography & Compliance
Accounts Requiring Immediate Review
4 Flagged
Geographic Risk Indicators
Charlotte NC — baseline
Bermuda — anomaly detected
Compliance Posture
Medium Risk
Key insight: Auto-label enforcement remains the largest compliance gap. Two policies must be promoted from Simulation to Enforce before the BMA audit.
Generated —
3
Critical Investigations
Immediate attention
4
High Priority
Needs ownership
4
Risky Users
Entra + Sentinel
27
Managed Assets
VMs · laptops · servers
Active Investigations
Grouped Live Signals
By entity
Network + Storage Correlation
Last 24h
Tunnel Stability Timeline — Harmony disconnects vs auth drift
Authentication Drift
Kerberos
78%
NTLM
22%
Recommended Next Move
NTLM usage is increasing on mrecorporatefiles. Investigate whether tunnel instability or device sign-in flow is driving fallback behavior before next migration step.
Incident Timeline
Identity → Network → Endpoint → Storage
Alert Stream
10
Devices Online
Active <1h
Open Incidents
3
Sentinel + Defender
Identity Risks
4
Entra risky accounts
Managed Devices
Defender + Azure VMs
Device Inventory by Type
Alert Volume by Source (24h)
Sign-in Failures (24h)
SigninLogs
Affected Users
Unique accounts
Top Error Code
Loading…
Conditional Access
Active
Entra CA policies enforced
Top Error Codes — 24h
Error CodeReasonCountAffected UsersSample IP
Users by Failure Count — 24h
UserFailuresError CodesIPsLast Failure
Sign-in Anomalies
UserIPLocationResultTime
Risky Users — Entra ID Protection
UserRiskDetailLast SeenAction
Active Tunnels
22
Harmony SASE sessions
Disconnects (24h)
23
8 from 1 device
Blocked Connections
47
Policy enforced
VNet Health
3/3
All reachable
VNet Traffic — 24h
Harmony Tunnel Status
DeviceUserLocationDurationStatus
Tunnel Disconnection Events — 24h per Device
Harmony SASE — Active Device Locations
Charlotte NC (14) Hamilton BM (3) Anomaly detected
Source: Perimeter81_CL  ·  Fields: device_hostname_s · agent_ip_s · user_email_s · eventName_s
Laptops
Intune managed
Azure VMs
All VMs in tenant
Devices Not in Compliance
Requires remediation
Shelf Inventory
Total across locations
Intune Compliance Status Live from Intune
Devices not in compliance
Connector errors
Service health
Configuration policies with errors or conflict
Client app install failures
Account status
Shelf Inventory by Location Autopilot group tags · Live from Intune
Charlotte
Wiped
New
Stale
Pending Reimage
Bermuda
Wiped
New
Stale
Pending Reimage
All Managed Assets
27 devices
#DeviceTypeUserComplianceLocationIP
Select a device
to see context
Open DLP Findings
0
Unresolved
Policies Active
3
Enforcing auto-label
Labels Applied (7d)
470
SharePoint / OneDrive
Labels Removed (7d)
16
2 without justification
Auto-Label Policy Status
Sensitivity Label Activity (30d)
Sensitivity Label Usage (applied, last 30 days)
Loading label usage…
Labels Removed
last 30 days
Labels Downgraded
last 30 days
Protection Change Audit Trail (30d)Every label removal or downgrade, with the recorded business justification
TimeUserActionLabel changeItemJustification
Loading audit trail…
SMB Conn Failures (24h)
DeviceNetworkEvents
Public Route Leakage
Should be 0 (Private only)
P Drive Lockouts (24h)
AADDomainServicesAccountLogon
Wrong Passwords (24h)
AADDS 0xC000006A
Account Lockouts + Wrong Password Events — 24h
TimeAccountError TypeError Code
Connection Failures — User + Device + Route
TimeDeviceUserRouteRemote URLRemote IP
Entra Kerberos Migration Status
File Share Access Log
DeviceUserEndpointTypeConnsAuthLast Seen
Critical
2
Sentinel incidents
High
3
Review today
Medium
2
Monitor
Resolved (7d)
14
Closed this week
All Incidents — Sentinel + Defender
IDTitleSourceSeverityEntityCreatedStatusMITRE
Alerts
7