Notification of when an account is logged in from outside an approved location.
Notification of when an account has been successfully accessed from a region where access is intended to be restricted. The event indicates that the account name and password have been used successfully and possibly by a malicious party.
Monitoring for rules that will forward emails to outside of the domain.
Notification of when different IPs are logged in to the same account.
The default security policy has detected unusual activity on the account and has restricted email sending functionality.
Notified when a user is added to an admin role.
Notification if a user’s MFA is disabled due to a compromise or verification if an admin is abusing their role.