Browse
On this page

Security alerts in the client portal

What a client reader sees on the Security page, and what one security event looks like opened up: the plain sentence, the step we took, and the one button.

You need A portal login as the account Owner, Primary Contact or IT Admin (User and Billing do not see Security)

  1. Overview and History

    Security has two tabs. Overview is the current picture. History lists security events once they are settled - handled or expired - so the two never show the same alert twice.

  2. Recent security activity

    Where settled security events are listed, newest first, once monitoring is running. This account has not granted Microsoft 365 consent yet, so the card explains that instead of listing events.

One alert, opened

  1. The alert's name and status

    Names what was found and shows one of three states next to when it was found: Handled, Being handled, or Needs your attention.

  2. What happened

    One sentence: what our tools saw, naming the account when we know it.

  3. What we did

    The step we took, or that we are still looking into it right now.

  4. What you should do

    Whether we need anything from you. Most of the time the answer is nothing.

  5. Contact button

    Opens a support message with this alert already named in it, so you never have to look up a reference number yourself.

Why it works this way

This account is directly managed, so the page tells the customer what we did and asks nothing back. An organization that runs co-managed IT gets a different bottom half on the exact same page: instead of What we did and What you should do, it asks "Was this you?" with two buttons, "This was me, dismiss" and "Acknowledge, we're handling it", and under "Need help?" an "Escalate" button. Every button press is written into the alert record the IT provider reads. Which half a reader sees is decided by one setting on their organization - never by their own role - so the same person sees the direct half at one client and the co-managed half at another.

Questions this page answers

What does this alert page show?

It is one page for one security event we saw on your systems. The top line names the event and shows where it stands: Handled, Being handled, or Needs your attention. Under that you get three short parts. What happened tells you what we saw. What we did tells you the step we took. What you should do tells you if we need anything from you, and most of the time the answer is nothing. The button at the bottom opens a support message with this alert already named in it, so you do not have to look up a code.

What do the buttons on a security alert do?

You see these buttons if your team runs IT with us. Was this you? has two buttons. Press "This was me, dismiss" when the activity was yours or your team's. We then close the alert. Press "Acknowledge, we're handling it" when your team is taking it from here. We then mark it as being handled. Under Need help? the Escalate button tells us you want us on it. It then opens a support message with this alert already named in it. Every button you press is written into the alert record your IT provider reads.

Was this helpful?

Last validated 2026-09-20