A login that looks wrong, at an hour that looks worse
Block it and you may lock out a colleague who is travelling. Ignore it and you may not. Both wrong answers are expensive, and the evidence that would settle it lives in four different consoles.
What actually happens
The hard part of this alert is not detection. Detection was immediate. The hard part is that the analyst has to choose between two irreversible actions with a fraction of the evidence.
A login succeeds with valid credentials from a geography the account has never used, at an hour the account has never been active. Nothing about the authentication itself failed. The credentials were correct.
The analyst on shift has a queue and a service level, and this alert looks like a dozen others that turned out to be someone on holiday with a roaming SIM. It also looks exactly like the first hour of a credential theft, because at this stage those two things are genuinely indistinguishable from the alert alone.
Settling it means checking the travel calendar or HR system, the device posture, whether the session is doing anything unusual, whether a colleague can vouch, and whether this pattern has appeared on other accounts recently. That is four or five consoles and a set of permissions the analyst may not have at three in the morning.
So the decision gets made on the balance of probabilities, and the balance of probabilities is usually right. The times it is wrong are the ones that end up in a breach report, and the reason it was wrong is almost never analytical skill. It is that the evidence was not reachable in the time available.
The organisational damage from the other failure mode is quieter. Locking out enough legitimate users trains the business to treat the security team as an obstacle, and that costs you cooperation you will need later.
This alert does not need a better detection model. It needs the evidence that already exists in four systems to arrive in one place, before the analyst has to choose.
The same alert, two ways
Detection was instant in both columns. The clock below measures how long it takes to earn a defensible decision.
Illustrative, not measured. The times below model a scenario built from the patterns we see in production estates. They are not timings recorded at a named customer. The point is the shape of the clock, not the totals: check it against your own last ten incidents.
Today, alert then console hopping
- 03:02Login succeeds from an unusual geography at an unusual hour. Alert raised.
- 03:02 ↓ 03:24WaitingAnalyst checks identity provider, then device posture, then travel records. Separate consoles, separate logins.
- 03:24Session activity reviewed. Nothing obviously hostile, nothing obviously benign.
- 03:24 ↓ 03:55WaitingAttempt to reach the user. No answer. Escalation to the duty manager.
- 03:55Decision made on balance of probabilities. Account left active, session monitored.
- 09:10User confirms the login when they come online. Alert closed as benign.
~55 minutes to a decision · and the same clock if it were hostile
With Sentinel investigating
- 03:02Login succeeds. Sentinel opens an investigation rather than queueing an alert.
- 03:04Identity provider, device posture, travel and leave records, session activity, and recent similar patterns across other accounts queried together.
- 03:05Device is a known enrolled device. No travel record. Session activity consistent with the account historical behaviour. One comparable pattern on another account this week.
- 03:06Sentinel calls the user directly for out-of-band confirmation rather than emailing them.
- 03:08User confirms. Session annotated, evidence bundle retained, geography added to the expected set with an expiry.
- 03:08No lockout, no page to the duty manager, and the same six minutes would have applied if the answer had been no.
~6 minutes to a decision · with the evidence attached either way
The number that matters is not fifty-five minutes against six. It is what those minutes buy in the hostile case, because the clock is identical whether the login is benign or not.
In the first column, a real credential theft gets nearly an hour of unobserved activity while an analyst moves between consoles. In the second, a hostile answer arrives at minute six with the account already staged for isolation, the blast radius mapped and the evidence bundle assembled.
The out-of-band voice contact is the step that actually resolves it. Everything else narrows the probability. Only reaching the human distinguishes a valid credential in the wrong hands from a colleague in an airport, and it is the step most SOCs cannot automate.
If the user does not answer, that is treated as a result rather than a dead end. Sentinel escalates with the isolation MOP staged, the affected systems mapped and the comparable pattern on the other account attached, so the duty manager decides from evidence rather than assembling it first.
Why the number is what it is
The number that matters is not fifty-five minutes against six. It is what those minutes buy in the hostile case, because the clock is identical whether the login is benign or not.
In the first column, a real credential theft gets nearly an hour of unobserved activity while an analyst moves between consoles. In the second, a hostile answer arrives at minute six with the account already staged for isolation, the blast radius mapped and the evidence bundle assembled.
The out-of-band voice contact is the step that actually resolves it. Everything else narrows the probability. Only reaching the human distinguishes a valid credential in the wrong hands from a colleague in an airport, and it is the step most SOCs cannot automate.
If the user does not answer, that is treated as a result rather than a dead end. Sentinel escalates with the isolation MOP staged, the affected systems mapped and the comparable pattern on the other account attached, so the duty manager decides from evidence rather than assembling it first.
The out-of-band voice contact is the step that actually resolves it.
Who decides to press go
Locking an account is irreversible in every way that matters to the person on the other end of it, so it is never taken automatically.
Reversible steps run under policy: evidence bundle assembled, session recording retained, account staged for isolation without executing, comparable patterns surfaced.
The isolation MOP is raised and held with the evidence bundle, the affected systems and the rollback path attached. A named human approves before the account is touched.
This does not remove the analyst from the decision. It removes the console hopping from the fifty minutes before the decision.
Successful authentication with valid credentials from an unused geography at an unused hour. No authentication failure. Account otherwise normal.
Identity provider, device posture, travel and leave records, session activity and comparable recent patterns across other accounts correlated into one picture.
Out-of-band voice contact placed to the user. Isolation MOP staged but not executed. Session recording retained regardless of the outcome.
Confirmed geography added to the expected set with an expiry. Comparable pattern on the second account promoted to its own investigation. Detection tuned against the confirmed outcome.
This is a platform capability, not a published customer deployment. The mechanism, which is correlated investigation across identity, change and telemetry followed by governed action with approval gating, is running in production today; see governed day-2 operations across 2,000+ nodes and closed-loop network automation. The security scenario above applies that same mechanism to an identity and access context. The timings shown are modelled, not measured at a named customer.
If the action carries no service impact
Reversible steps run under policy: evidence bundle assembled, session recording retained, account staged for isolation without executing, comparable patterns surfaced.
If it locks an account or terminates a session
The isolation MOP is raised and held with the evidence bundle, the affected systems and the rollback path attached. A named human approves before the account is touched.
What Sentinel did, step by step
- ObserveSuccessful authentication with valid credentials from an unused geography at an unused hour. No authentication failure. Account otherwise normal.
- InvestigateIdentity provider, device posture, travel and leave records, session activity and comparable recent patterns across other accounts correlated into one picture.
- ActOut-of-band voice contact placed to the user. Isolation MOP staged but not executed. Session recording retained regardless of the outcome.
- OptimizeConfirmed geography added to the expected set with an expiry. Comparable pattern on the second account promoted to its own investigation. Detection tuned against the confirmed outcome.
Bring us an alert you had to judge
We will map what evidence existed at the time and how long it took to reach.