Sourcepass Blog

What Petra Monitors and How Sourcepass Responds

Written by Mark Calzone | Aug 25, 2026

As organizations continue to adopt Microsoft 365 as their primary platform for communication, collaboration, and data management, identity has become one of the most critical areas of cybersecurity. Modern attacks increasingly target user accounts rather than devices or networks, allowing threat actors to operate through legitimate credentials and trusted access.

This shift has elevated the importance of Identity Threat Detection and Response (ITDR), a security discipline focused on identifying compromised accounts, suspicious user behavior, and account misuse within cloud environments. Petra Security is designed to provide behavioral identity threat detection and response for Microsoft 365 environments, helping detect risks that may not be visible through traditional security controls alone. Sourcepass leverages Petra as an additional layer of visibility and response focused on Microsoft 365 identities and user activity.

 

Why Identity Monitoring Matters in Microsoft 365

Microsoft 365 has become the operational hub for many small and mid-market organizations.

A single user account can provide access to:

  • Exchange Online email
  • Microsoft Teams communications
  • SharePoint sites
  • OneDrive files
  • Business applications integrated with Microsoft Entra ID
  • Sensitive organizational data

While Microsoft provides robust security controls such as multifactor authentication (MFA), Conditional Access, and identity protection capabilities, attackers increasingly focus on compromising legitimate user accounts.

Once authenticated, malicious activity may appear indistinguishable from normal business operations.

That creates a need for continuous monitoring of user behavior, account activity, and signs of identity compromise.

 

What Petra Monitors in Microsoft 365

Petra is designed to monitor identity-related activity within Microsoft 365 environments and identify indicators of compromise, account misuse, and suspicious behavior. According to Sourcepass program documentation, Petra functions as a behavioral identity threat detection and response platform focused on monitoring user activity after authentication rather than solely validating access.

 

Compromised User Accounts

A compromised account remains one of the most common starting points for cybersecurity incidents.

Petra is intended to identify indicators that may suggest:

  • Stolen credentials
  • Phished accounts
  • Account takeover attempts
  • Attacker persistence activities
  • Unauthorized account use

According to Sourcepass program materials, Petra helps monitor for compromised accounts and suspicious sign-in behavior that could indicate unauthorized access within Microsoft 365.

 

Business Email Compromise Activity

Business Email Compromise (BEC) attacks frequently leverage legitimate accounts to conduct fraud, impersonation, or unauthorized financial requests.

Sourcepass documentation identifies BEC detection as a core use case of Petra's identity monitoring capabilities, specifically noting the platform's focus on fraudulent messages, mailbox rule manipulation, invoice fraud attempts, and payment fraud activity originating from trusted accounts.

 

Suspicious Sign-In Behavior

Not every successful login represents legitimate activity.

Petra monitors for unusual authentication patterns and behaviors that may indicate:

  • Unauthorized access
  • Compromised credentials
  • Session abuse
  • Elevated account risk

Behavioral analysis helps identify patterns that differ from normal user activity and may warrant investigation.

 

Mailbox Rule Manipulation

Attackers frequently create malicious mailbox rules after gaining access to an account.

Common objectives include:

  • Hiding communications
  • Forwarding messages externally
  • Deleting security alerts
  • Maintaining long-term persistence

The Sourcepass Petra documentation specifically references detection of mailbox rule manipulation as part of the platform's identity threat monitoring capabilities.

 

Unauthorized Application Consent

Modern identity attacks increasingly involve malicious or unauthorized application permissions.

Attackers may convince users to grant access to applications that maintain persistent access to email and data.

Monitoring for unexpected permission changes and user behavior provides additional visibility into this risk area.

 

Access to Microsoft 365 Resources

According to Sourcepass program materials, identity monitoring extends across Microsoft 365 services, including:

  • Exchange Online
  • Microsoft Teams
  • SharePoint Online
  • OneDrive

This visibility helps identify suspicious behavior associated with trusted identities across the applications employees use every day.

 

How Sourcepass Responds to Identity Threats

Detection alone does not reduce risk.

Effective cybersecurity requires a combination of visibility, investigation, containment, and remediation.

Sourcepass positions Petra as part of a broader managed security approach focused on helping clients identify and respond to identity-related threats within Microsoft 365 environments. The program documentation specifically describes Petra as supporting both detection and response activities.

 

Investigation and Validation

When suspicious activity is identified, the first step is understanding whether the behavior represents legitimate business activity or a security concern.

According to Sourcepass materials, Petra provides visibility into suspicious account activity and compromise indicators that can support security investigations and incident analysis.

This investigative context helps reduce uncertainty and enables a more informed response process.

 

Threat Containment

The Sourcepass Petra program highlights faster containment and remediation of identity threats as a primary benefit of the platform. The goal is to limit the impact of suspicious or potentially malicious activity before it can spread throughout the Microsoft 365 environment.

An effective response strategy focuses on limiting attacker access while preserving business continuity.

 

Remediation Support

According to Petra's MSP-focused positioning referenced within the Sourcepass program materials, the platform incorporates remediation and response capabilities intended to support faster resolution of identity-related security incidents.

Remediation activities may focus on restoring trust in identities, removing unauthorized access, and addressing behaviors associated with account compromise.

 

Operational Visibility

Beyond individual incidents, continuous monitoring provides organizations with a better understanding of identity risk across their Microsoft 365 environment.

This visibility helps support:

  • Security program improvements
  • Identity governance initiatives
  • Risk management programs
  • Compliance readiness efforts
  • Security awareness programs

The objective is not only responding to threats but reducing the likelihood of future incidents.

 

The Business Value of Continuous Identity Monitoring

For executives and operational leaders, cybersecurity investments should be evaluated based on measurable outcomes.

Identity monitoring can help organizations:

 

Reduce Time to Detect Account Compromise

Earlier detection allows organizations to investigate and address suspicious activity before it develops into a larger security incident.

 

Improve Incident Response Efficiency

Behavioral monitoring provides additional context that can accelerate investigations and improve response workflows.

 

Strengthen Microsoft 365 Security

Identity monitoring complements foundational Microsoft 365 security controls such as MFA, Conditional Access, and Microsoft Defender.

 

Support Compliance and Cyber Insurance Requirements

The Sourcepass Petra program identifies compliance, audit, and cyber insurance readiness as important outcomes associated with identity monitoring and response capabilities.

 

Encourage Better Security Behavior

Security is not solely a technology challenge.

Organizations that monitor identity activity often gain insights that support:

  • User training initiatives
  • Access governance improvements
  • Privilege management decisions
  • Policy refinement
  • Risk reduction programs

The result is stronger organizational resilience over time.

 

Identity Protection Requires Visibility and Response

Most modern cyber incidents involve some form of identity misuse, compromised credentials, or unauthorized account activity.

As organizations become increasingly dependent on Microsoft 365, security strategies must extend beyond login protection and access controls. Organizations need visibility into how identities behave after authentication and the ability to respond when those behaviors indicate elevated risk.

Petra's role within the Sourcepass security approach is to provide behavioral monitoring and identity threat detection across Microsoft 365 environments, helping identify compromised accounts, business email compromise activity, suspicious user behavior, and unauthorized access. Combined with investigation and response processes, this additional layer of visibility helps organizations strengthen identity security while reducing operational risk.

 

FAQ

What does Petra monitor in Microsoft 365?

According to Sourcepass program documentation, Petra monitors identity-related activity within Microsoft 365 environments, including compromised accounts, suspicious sign-in activity, business email compromise indicators, mailbox rule manipulation, unauthorized access, and user behavior anomalies.

Does Petra monitor Microsoft Teams, SharePoint, and OneDrive?

Yes. Sourcepass documentation states that Petra provides monitoring related to identity-based threats across Microsoft 365 services, including Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive.

How does Petra help detect business email compromise?

Petra is designed to identify indicators associated with business email compromise, including suspicious account behavior, fraudulent communications, mailbox rule manipulation, invoice fraud attempts, and payment fraud activity originating from trusted accounts.

What is Identity Threat Detection and Response?

Identity Threat Detection and Response (ITDR) is a cybersecurity discipline focused on detecting, investigating, and responding to threats involving user identities and authenticated accounts. ITDR helps organizations identify compromised accounts and suspicious activity that may be missed by traditional security controls.

How does Sourcepass respond to identity threats?

According to Sourcepass program materials, the response process includes threat detection, investigation support, containment, remediation assistance, and ongoing monitoring intended to reduce the impact of identity-related security incidents.

Does Petra replace Microsoft 365 security controls?

No. Identity threat detection is intended to complement existing Microsoft 365 security controls such as multifactor authentication, Conditional Access, Microsoft Defender, and identity governance practices. Effective cybersecurity typically combines preventive controls with continuous monitoring and response.

Why is continuous identity monitoring important?

Continuous identity monitoring helps organizations detect compromised accounts, suspicious behavior, business email compromise activity, and unauthorized access more quickly. Faster detection can improve response effectiveness and reduce overall organizational risk.