> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/sign-in-threat-detected.md).

# Sign In Threat Detected

Detects successful user sign-ins associated with a Microsoft Entra ID Risk User event, which may indicate unauthorized access.

The allowlist may be configured under Check Settings to focus on specific severity levels, enabling you to reduce the associated noise.

See also: [Duo Sign In Threat Detected](/understanding-check-failures/oort-insights/identity-threat-detection-insights/duo-sign-in-threat-detected.md) | [Okta Sign In Threat Detected](/understanding-check-failures/oort-insights/identity-threat-detection-insights/okta-sign-in-threat-detected.md)

**Recommended Actions**

Please investigate this suspicious sign-in to confirm the account is not compromised. If the user is compromised, consider killing all sessions and add the user to a quarantine group.

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)
