CyberSentry at a glance
The CyberSentry Overview page, its fleet-wide stats and lists, the four pages under it, and the Security Awareness program once it is turned on.
Fleet security stats
Four counts across every client you manage: Needs human review, High Severity, Filtered by Elise, and Sign-in monitoring, which shows how many clients have the Microsoft license CyberSentry's strongest detections need. Click the Needs human review, High Severity, or Filtered by Elise tile to open Triage filtered to that same set.
Security coverage gaps
Security coverage gaps lists every client that is in scope for CyberSentry monitoring but does not have sign-in threat monitoring active yet, with a count and a Configure coverage link. Which clients are in scope at all is set under Settings > Clients > Client Boards.
Top at-risk clients
Top at-risk clients ranks your managed clients by open alert count, so a fleet review can start with the client that needs attention first. It reads "No open alerts across any client" when the fleet is clean, as it is here.
Recent high-severity alerts
Recent high-severity alerts lists the fleet's most severe recent findings regardless of which client they belong to, so a fleet-wide check does not mean opening every client one at a time. It reads "No high-severity alerts" when there are none, as it is here.
Triage
Triage is Elise's investigation view of every Microsoft 365 sign-in and directory signal CyberSentry sees: alerts still needing human review, and everything Elise already cleared as noise, each with the confidence math behind the call. It is not a ticket queue, and it never opens a ticket or sends a notification for any alert on its own.
Posture
Posture lists every managed client's Microsoft Secure Score side by side, read directly from that client's own Microsoft 365 connection rather than a score the portal invents. A client appears here once its Microsoft 365 integration is connected and synced. The actual hardening actions live in that client's own Microsoft security center; this page is the fleet-wide scoreboard for deciding who to harden first.
Response Rules
Response Rules is where operator-authored IF/THEN security automation lives, alongside the always-on Confidence Engine row at the top of the page, which scores every signal from 0 to 100 and is the primary automatic detection underneath the rules you write. Every rule, and the Confidence Engine, share the same three states: Disabled, Monitor, and Live. Monitor records what a rule would have done without touching any account; only a deliberate switch to Live lets it actually lock an account, revoke sessions, or open a ticket.
Awareness
Awareness is the Security Awareness program: an annual training written for each client's industry and jurisdiction, weekly Micro-Trainings, and Training Records, the completion evidence you can hand to an auditor or a cyber-insurance underwriter. The program ships off, and while it is off nothing runs: no annual training can be written, no weekly Micro-Training is generated, nobody is enrolled or reminded, and clients see no Security Training page. Turning it on runs a five-lesson wizard reached from this same page, which teaches the program and then walks three things: put Security awareness training on the service plans that should include it, which is what decides who is in the program; set each client's Industry; and connect a training mailbox so assignment and reminder email can send. The last lesson flips the switch on. The switch itself lives at Settings, then Security, then CyberSentry, if you ever need to turn the program back off. The next screenshot shows the three pillars once it is live.
Awareness once the program is on
Security Awareness Training
The compliance pillar: one AI-authored annual course per client, framed in that client's regulatory language, with every employee automatically enrolled once it is published. The tile counts completions across all clients and reads 0 here because this tenant has turned the program on but not yet authored a training.
Micro-Trainings
A short weekly nudge generated every Monday for each client industry in scope: one timely topic and a one-question check. It is an internal surface for your team, not a client-facing page, and the tile reads 0 until the weekly job has run.
Training Records
The compliance artifact: every annual-training completion, recorded per user, exportable as a CSV for an auditor or a cyber-insurance renewal. A record stays on file even after a client leaves the program. It reads 0 here because no employee has completed a training yet.
Why it works this way
Triage never opens a ticket or sends a real-time notification for any alert, however severe it looks. Only two doors do that: an operator-armed Response Rule with the matching action, or the Confidence Engine promoted to Live. Triage is where you investigate what already happened or would have happened, not where you make it happen.
The Confidence Engine sits above the hand-written Response Rules on purpose. It is the primary, always-on detection, and the rules below it are specific IF/THEN overrides layered on top of that baseline.
Which clients belong to the Security Awareness program is decided on Billing > Service Plans, not on this page. A client is in the program the moment their active plan includes Security awareness training, and drops out the moment it doesn't, except for training records already on file, which stay as historical evidence even after a client leaves the program.
CyberSentry itself only exists on an instance set up for the MSP module. On an instance set up for a different module, this whole area, stats and all, stays hidden rather than showing up empty.
Questions this page answers
What does the Security Overview page show?
CyberSentry → Overview is your top security page. It covers every client you manage. It shows alerts to review. It shows high-severity counts. One tile, "Filtered by Elise" by default, shows how much noise the assistant already cleared - the name follows whatever you call your assistant. It also shows sign-in coverage, coverage gaps, at-risk clients, and recent severe alerts.
How do I get from an overview stat to the actual alerts?
Click any top stat tile: Needs human review, High Severity, or Filtered by Elise. Each one opens CyberSentry → Triage, filtered to that set. The lists below link straight to a client or an alert.
Why don't I see a Security area at all?
CyberSentry is a feature for the MSP module. On an instance set up for a different module, this whole section stays hidden. It never shows and fails.
What is Security Triage?
Elise's triage of your fleet's Microsoft 365 security signals - the cleared noise and the escalations, with the confidence math shown for each. It is where you INVESTIGATE, not a ticket door or a notification door: Elise never opens a ticket or sends a real-time push herself, on any alert. A genuine threat becomes a ticket, or triggers a notification, when it crosses one of two doors you control - an armed Response Rule, or the AUTO confidence-band engine promoted to Live (both under CyberSentry → Response Rules). Triage lets you see everything Elise saw and why it did or didn't act, whether or not either door has fired yet.
Why are most alerts marked "cleared"?
Most sign-in and directory activity is benign or expected, and Elise clears it so it doesn't drown the real signal. A cleared alert isn't hidden - it's recorded with the confidence it scored and the factors behind it, so you can audit the decision. Only activity that reaches an escalation band surfaces as something to act on.
How does a security alert become a ticket?
Through exactly one of two doors, never Triage itself. An operator-armed Response Rule with the "Open ticket" action (CyberSentry → Response Rules) tickets whatever pattern it matches. The AUTO confidence-band engine, promoted to Live (CyberSentry → Response Rules → Confidence Engine), scores every finding 0-100 and its bands decide what fires, open_ticket included. Either way the ticket lands on the security board you set in Settings → Security → CyberSentry, in your normal workflow (assignment, SLA, replies), while Triage stays the security-specific investigation surface. A fresh instance opens no automatic tickets until you arm one of these two doors.
Why didn't anyone get a real-time notification for this alert?
The same two doors that open a ticket are also the only two doors that push a real-time notification (bell + email) - Triage clears noise, annotates, and raises the alert, but it never pages anyone on its own initiative. An operator-armed Response Rule with the "Notify" action (CyberSentry → Response Rules) pushes for whatever pattern it matches. The AUTO confidence-band engine, promoted to Live (CyberSentry → Response Rules → Confidence Engine), can include security.notify in a band's actions. A fresh or lightly-armed instance - including one whose confidence engine is still in Monitor - sends no real-time pushes at all until you arm one of these two doors; the alert stays fully visible on this page and in the periodic Cleared-by-Elise digest either way. That's the intended "ships quiet" default, not a gap.
What does Security Posture show?
Microsoft Secure Score for every managed client, side by side. It's a fleet-wide read of how well each tenant's Microsoft 365 security controls are configured - a fast way to spot the clients most in need of hardening.
Where does the score come from?
Directly from Microsoft Secure Score via each client's Graph connection - it's Microsoft's own measure, not a number this portal invents. A client only appears with a score once its Microsoft 365 integration is connected and has been synced.
How do we raise a client's score?
By applying Microsoft's recommended improvement actions in that tenant (MFA coverage, legacy-auth blocking, admin-role hygiene, and so on). Posture is the scoreboard; the specific actions live in the client's Microsoft security center. Use the fleet view to prioritise which tenants to harden first.
What are Response Rules?
Operator-authored IF/THEN security automation (SOAR-lite). A rule watches CyberSentry's event stream and, when a sequence of conditions happens in order, runs one or more "effects" - lock the account, revoke sessions, open a ticket, notify. You build them as a map: WHEN these steps happen → THEN run these actions. Rules ship inert (Monitor + disabled) and only act when you deliberately arm them.
What is the "Confidence Engine" row at the top of this page?
It's the always-on detection spine, the "glass box." Every security signal is scored into a 0 to 100 confidence, and thresholds decide what that confidence fires. It sits ABOVE the hand-written response rules on purpose: it is the primary automatic detection, and the response rules below are specific IF/THEN overrides you author on top. On this page it appears as a single row, marked "Auto," with a Monitor on/off toggle - the toggle only ever arms Monitor, never Live. Open the row to reach the Confidence Engine page, where its two parts live under the "Auto Response Thresholds" section: Factor Weights (how a signal becomes a number) and Confidence Bands (what that number does). Arming it for real is a separate, deliberate "Promote to Live" step on that page.
What is the difference between Monitor and Live mode?
Monitor records what the rule WOULD do every time it matches, nothing is locked, revoked, or notified. It is a safe dry-run you can watch in the run history. Live actually runs the effects on real accounts. The rule's state is one three-way switch, Disabled / Monitor / Live: always start in Monitor, watch the run ledger (or use "Test against history"), and only switch to Live once you trust it. Switching to Live also asks you to confirm, because it then acts automatically.
What do the Disabled / Monitor / Live states mean?
Every response rule (and the automation as a whole) has three states. DISABLED - the rule does nothing; it does not even evaluate. MONITOR - the rule evaluates live and records what it WOULD have done in the run history, but never touches an account (a safe dry run). LIVE - the rule runs its actions for real: sessions revoked, accounts locked, tickets opened. Always ride a new rule in Monitor, watch the run ledger, and switch to Live deliberately - the page asks you to confirm because Live acts with no human approval.
How should I roll out thresholds safely?
Calibrate in Monitor, then arm. Leave new detection in Monitor and watch the run history / backtest against a client's real recent activity to see the blast radius and what the guards would block. Once the confidence math and bands behave the way you expect, promote to Live one step at a time. This "calibrate-in-monitor-then-arm" order is the whole point of the three states - you never guess in production.
What is Security Awareness?
The CyberSentry Security Awareness program for your clients' employees: an annual Security Awareness Training per client (AI-authored in the client's regulatory language, assigned to everyone there, reminded, and recorded), weekly Micro-Trainings (a 2-minute read plus a short quiz per client industry), and Training Records - the per-user completion evidence you hand to an auditor or cyber-insurance underwriter. Each card here opens its pillar.
How do I turn the program on (or off)?
Security Awareness ships switched off. While it is off, nothing runs. No training gets written. No weekly Micro-Training is generated. Nobody is enrolled or reminded. Your clients see no Security Training page. This landing shows the "Turn on Security Awareness" wizard instead of the pillars - run it. The wizard explains how the program works. Then it walks you through three things: put Security awareness training on the service plans that should include it, since that decides who is in the program; set each client's Industry; and connect a training mailbox for assignment and reminder email. The last step flips the switch on. You can also flip it at Settings, then Security, then CyberSentry, if you need to turn the program off again. Turning it off stops all of the above, but it never deletes a completion record.
Which of my clients are in the awareness program?
The ones whose service plan includes it. Open Billing > Service Plans, open a plan, and turn on "Security awareness training" under Included functions: every client with an active subscription on that plan is then in scope. Coverage follows what the client bought, so it changes the day their plan does, and a client can be Managed without being in the program. While no plan carries it, nobody is in scope, and that is deliberate: the New Training picker lists no clients, the weekly micro-trainings generate nothing, and the daily sweep enrolls and reminds no one. Training Records is the one exception, and it is unscoped on purpose: a completion already written is historical evidence, so it stays on the record even if the client later drops the plan.
How is the content tailored to each client?
Two fields on the client's edit page (Clients > the client > Edit > Company Information): the billing Country, under Billing Address, and the Industry. Leave Country on 'Use instance default' and it follows your Default Client Country under Settings > Company > Company Profile, so an MSP whose clients are all in one country sets it once rather than per client. Country comes first, because it decides which body of law applies at all, and the industry then picks the frameworks within it. A US insurer maps to GLBA, the NAIC Model Law and HIPAA; a Canadian insurer maps to OSFI Guideline B-13 and PIPEDA; an Ontario clinic maps to PHIPA and PIPEDA. Every generated training is framed in that language and is explicitly told not to cite another country's statutes. A client with no country set gets vendor-neutral content (ISO 27001, SOC 2, NIST CSF) rather than American law, and a client with no industry set gets that country's general baseline.
What are Micro-Trainings and who sees them?
Every Monday the weekly job generates one short lesson plus a 1-2 question quiz per distinct client industry (and one generic set). Right now they are an internal surface - your team can read them and take the quiz here; a client-facing door is a planned follow-on. Generate This Week re-runs the job on demand; it is idempotent, so an existing week/industry is never regenerated.
What is this page, and how do I export it?
Every annual-training completion across all clients, newest first - the compliance artifact. The tiles count the whole table; the list shows the most recent 500. Use Export on the list to download the full set as CSV for an audit or insurance renewal. Records are kept even after a client is offboarded or deactivated - they are historical evidence.
Was this helpful?