SenseOn Platform: Sep 2025
Microsoft 365 user response actions are now available to every organisation, so you can revoke sessions and disable Entra ID accounts from a case in Investigate. The Investigate case feed brings every case into a single list, with badges marking Reflex and Antimalware cases. Endpoint Protection exclusions are clearer to set up, and Experience fits wide observations on screen more neatly.
What's new
Microsoft 365 user response
Connect your Microsoft account as an Entra ID User Containment integration in Data Connectors, then act on Microsoft 365 users straight from a case. Open the action menu on a user in Investigate to view their Microsoft details, revoke their sessions, or disable their account and re-enable it later, and see the history of actions taken against them. The team list in Settings shows which users have connected a Microsoft account.
- Investigate: the case feed shows all of your cases in a single list, with the case totals in its heading. Reflex and Antimalware cases carry a badge, so you can pick them out at a glance.
What's improved
- EPP Exclusions: file path and hash exclusions accept a path, a hash or both. The form now reads AND/OR between the two fields and makes clear that hashes are SHA-1.
- Hunt Lab: run queries that use the full range of ClickHouse SQL, such as window functions and array and JSON functions. Contact SenseOn to request access.
- Experience: each entity is sized to fit its content, so wide network observations fit on screen without scrolling sideways.
- Experience and Investigate: long observation titles wrap to fit the space available.
This round-up covers SenseOn Platform 4.52 and 4.53.