[THEME] Monitoring
The Monitoring theme activates alerts for changes in your Microsoft 365 environment that could lead to unauthorized access or data exposure.
What does Attic do?
Attic continuously monitors critical configuration changes and access patterns to detect potentially suspicious administrative activity.
The checks in this theme cover:
- Detection of newly added delegated admin relationships
- External users with elevated privileges are identified
- Public SharePoint sites are detected and reported
- Changes to Conditional Access policies are monitored
Why is this important?
Attackers who gain access to a tenant often make configuration changes to maintain persistence or escalate their privileges. By monitoring for these changes in near real-time, your organization can quickly detect and respond to unauthorized modifications before they lead to a full breach.
Checks in this theme
| ID | Check |
|---|---|
| CHK-1051 | Delegate Admins |
| CHK-1131 | Guest users with role assignment |
| CHK-1520 | Public SharePoint sites |
| CHK-1168 | Monitor Conditional Access |