Solutions / Identity — ITDR

Centeye Gatewatch™ — identity threat detection & response, first-class on Microsoft and Google.

Most intrusions begin with a valid login, not an exploit. Centeye reads the identity providers’ live event streams, calls the account takeover while it’s happening, and ends it — sessions revoked, account locked, credentials reset, the attacker’s MFA method removed — then re-reads the provider to confirm.

Microsoft Entra IDGoogle WorkspaceAPI connection · minutes
This surface’s chapter of the attack
Sign-in, new country2:17 PM · impossible travel
Token replay2:17 PM · session hijack signal
New inbox rule planted2:23 PM · persistence
Takeover calledone account · one attacker
Evictedsessions revoked · MFA reset
What your clients get

Detected live. Ended on both providers.

Account takeover detection from live provider signals

Centeye consumes the identity providers’ own event streams and calls the takeover from the signals that carry it:

  • Risky sign-ins & impossible travel — a login from two countries an hour apart, a token used from the wrong device, a pattern that breaks the user’s established history.
  • MFA-fatigue detection — repeated push-prompt bombardment engineered to extract a tired “approve.”
  • Session hijacking & token-theft (AiTM) signals — replay and adversary-in-the-middle indicators read from the identity provider.
  • Malicious inbox rules — the forwarding and delete rules attackers plant for persistence and fraud cover.
  • Rogue OAuth app detection — third-party grants quietly given access to mail and files: the persistence layer of a modern takeover.
  • Credential exposure — monitoring for leaked and infostealer-harvested credentials tied to the tenant.

live IdP streams · Entra ID + Google Workspace

Both identity providers, first-class

Most identity tools are Microsoft-first with Google bolted on — or absent. Centeye treats Microsoft Entra ID and Google Workspace as equal citizens: the same detections, the same response verbs, the same console. For a provider with a mixed client book, that is the difference between operating one product and two.

Response that ends the takeover — and proves it

Alerts do not evict an attacker; response verbs do. Centeye executes them within your policy, then re-reads the identity provider itself to verify the session is gone and the door is shut.

  • Revoke all sessions — evict stolen tokens everywhere at once.
  • Compromised-user lockout — disable or suspend the account.
  • Forced password reset — automated, as a response action.
  • MFA method reset — remove the authenticator the attacker enrolled.
  • Conditional access / geo-fence policy — fence a compromised account to safe locations immediately (Entra ID).
  • Temporary admin-role removal — de-escalate a compromised administrator (Google Workspace).

stage → approve → execute → verify · provider re-read

How it works

Connected in minutes. Reporting the same day.

Connect the tenant

An API connection to Microsoft Entra ID and/or Google Workspace — minutes, no end-user impact.

Review the baseline findings

Risky sign-ins, rogue OAuth grants, and takeover patterns surface from day one in watch-only mode — evidence before any response is armed.

Arm the response

Choose which verbs run pre-authorized and which route to approval — per action class, per client.

Kavach · on this surface

Calls the takeover, stages revoke-sessions + lockout + MFA reset as one governed play, executes on approval or within policy, and re-reads the provider to prove eviction.

Argus · for the client

Answers “is the account safe now?” with the evidence, and documents the response for the client file, the post-incident review, and the cyber-insurance record.

Common questions

What MSPs ask us first

We have Entra ID P2 — isn’t identity covered?

P2 is a strong sensor with a policy engine — on Microsoft only, at tenants licensed for it, with key response steps still manual (an MFA method reset is an administrator clicking in a portal). Centeye operates the full detection-to-response loop on both providers and correlates identity with email and endpoint telemetry. Keep P2; Centeye is the layer that acts on it.

How is a compromised Microsoft 365 mailbox detected?

From converging identity and mailbox signals: an anomalous sign-in, followed by a new inbox rule, an unusual OAuth grant, or outbound patterns that break the user’s history — correlated into one incident rather than four low-severity alerts.

Can it act without us?

Only as far as the response mode you set — per action, per client. High-impact verbs default to approval, and every execution is logged and reversible where the provider allows.

What does the client’s staff see?

End users see nothing — detection and response happen at the identity provider. If the client runs an internal IT or security team, give them the same evidence view your analysts have and route approvals to them; notification is policy, not an afterthought.

Connect a tenant in minutes.

Watch-only first — review every risky sign-in and rogue OAuth grant you're not seeing today, before arming a single verb.