Detect faster. Investigate smarter. Respond automatically.
Monitor AI-analyzed email events, review workflow health, and investigate security detections through one protected analyst experience.
Protected analyst workspace
Authenticate with Microsoft Entra ID to access AI email security events and workflow telemetry.
AI security summary
Current detection and response telemetry
- High
- Medium
- Low
- Unrated
Select “Load summary” to chart the last 90 days.
Every email is checked against threat intelligence, and emails that are not flagged are also assessed by the AI. The response depends on that result.
- Automatic
- Low or Medium risk. Recipients are alerted automatically.
- Analyst
- High risk or flagged by threat intelligence. An analyst chose Notify User, Delete, or Not a Threat.
- No action
- High risk or flagged, but the analyst approval timed out or failed.
Select “Load summary” to retrieve AI email security metrics.
Investigation events
Last 30 days, with detections treated as High Risk
AI processing pipeline
Logical email analysis stages
Analysis capabilities
AI email security decision context
Workflow health
Processing and orchestration status
Select “Check health” to retrieve workflow status.
Event investigation
Retrieve a specific AI email security event
Enter an Event ID, or choose Investigate on an event in the list, to open its case view.