| User | User Principal Name | Risk Level | Risk State | MFA | Last risky sign-in |
|---|---|---|---|---|---|
| Jenna Harper | j.harper@innovagroup.tech | High | At risk | Yes | 14m ago |
| Manvir Singh | m.singh@innovagroup.tech | Medium | At risk | Yes | 3h ago |
| Tom Ackroyd | t.ackroyd@innovagroup.tech | Medium | Confirmed safe | No | 6h ago |
| Priya Nair | p.nair@innovagroup.tech | Low | Remediated | Yes | 1d ago |
| Craig Bell | c.bell@innovagroup.tech | Low | Dismissed | Yes | 2d ago |
| Device | OS | Owner | Reason | Last Sync | State |
|---|---|---|---|---|---|
| INV-LAP-042 | Windows 11 | t.ackroyd | Defender signature outdated | 5h ago | Non-compliant |
| INV-LAP-118 | Windows 11 | l.dawson | BitLocker not enabled | 1d ago | Non-compliant |
| INV-IPAD-07 | iPadOS 17 | reception | OS version below minimum | 9d ago | Not checked in |
| INV-LAP-090 | Windows 10 | c.bell | Password policy not met | 2d ago | Non-compliant |
| INV-AND-15 | Android 13 | field | Rooted device detected | 4h ago | Non-compliant |
| Detection ID | Threat | Detection Source | Recipient | Severity | Detected |
|---|---|---|---|---|---|
| MDO-4471 | Credential phish (QR) | Anti-phishing | accounts@innovagroup.tech | High | 22m ago |
| MDO-4468 | Malware attachment | Safe Attachments | t.ackroyd@innovagroup.tech | High | 2h ago |
| MDO-4459 | Malicious URL | Safe Links | sales@innovagroup.tech | Medium | 4h ago |
| MDO-4452 | Spoof / impersonation | Anti-phishing | j.harper@innovagroup.tech | Medium | 6h ago |
| MDO-4448 | Spam campaign | Zero-hour purge | multiple | Low | 8h ago |
| Incident ID | Title | Severity | Status | Assigned To | Detected |
|---|---|---|---|---|---|
| INC-2091 | Multi-stage identity attack | Critical | Active | SOC — S. Watson | 14m ago |
| INC-2088 | Privilege escalation attempt | Critical | Triage | Unassigned | 1h ago |
| INC-2085 | Email-borne malware wave | High | Active | SOC — S. Watson | 2h ago |
| INC-2079 | Anomalous travel · 2 users | High | Active | Unassigned | 3h ago |
| INC-2074 | Device compliance breach | Medium | Resolved | Intune auto | 5h ago |
| Policy Name | Condition | Threshold | Last Triggered | Today | State |
|---|---|---|---|---|---|
| Critical Alerts Monitor | critical alert count | ≥ 1 | 14m ago | 2 | |
| Risky User Detected | risk level = high | ≥ 1 | 14m ago | 1 | |
| Sign-in Anomaly | impossible travel | ≥ 1 | 3h ago | 1 | |
| MFA Coverage Drop | mfa coverage % | < 85% | — | 0 | |
| Admin Role Change | directory role assigned | any | 1h ago | 1 | |
| Email Threat Surge | malware detections/hr | > 10 | 2h ago | 0 | |
| Device Compliance Breach | non-compliant count | > 15 | 5h ago | 0 | |
| Stale Device | no check-in days | > 30 | 1d ago | 0 | |
| Insider Risk Alert | unusual data access | score > 70 | — | 0 |
| Control | Framework | Category | Status |
|---|---|---|---|
| Phishing-resistant MFA for admins | CIS 6.5 | Identity | Not met |
| Disk encryption on all endpoints | ISO A.8.24 | Devices | Partial |
| Privileged access reviews (PIM) | NIST PR.AA | Identity | Partial |
| DLP policy for sensitive data | SOC 2 CC6.7 | Data | Not met |
| Audit log retention ≥ 1 year | CIS 8.10 | Governance | Met |
| ID | Service | Title | Classification | Status |
|---|---|---|---|---|
| EX912045 | Exchange Online | Delays delivering mail in EMEA | Advisory | Investigating |
| MO911872 | Microsoft 365 apps | Some users unable to activate | Advisory | Restored |
| TM910233 | Microsoft Teams | Presence status delayed | Advisory | Restored |
This view is mapped to a real page in the app — wire it up next in the same pattern as the built-out tabs.