Check whether a user's sign-ins look suspicious
Ask for a security investigation on the person. It reports what it checked, what it skipped and why, so read the completeness before the conclusion.
Asking Avvi for a security investigation on a named person runs about ten checks together, covering sign-in history and failures, risk state and risk detections, multi-factor status, mailbox settings, SharePoint sharing, and directory changes.
The result reports what each check found and also what it could not do. A check that was skipped is labelled as skipped rather than quietly counted as clean.
Reading that completeness before the conclusion is the difference between an answer and a guess. On a client without the right Microsoft licensing, several of the checks cannot run at all.
Before you begin
Have the person’s email address. Investigations are per person.
Know what prompted the question. Somebody reporting an unexpected password prompt and somebody’s contacts receiving spam lead to different follow-ups.
Run the investigation
- Open chat and check the client.
- Ask for a security investigation, naming the person. For example: run a security investigation on jane@example.com, her contacts are getting spam from her.
- Read which checks completed, which were skipped, and which failed.
- Read the recommended actions, which are drawn from what the checks found.
Nothing about the person or their account is changed. One thing on the client’s tenant can be: the first investigation may switch on SharePoint audit collection if it was not already running, because otherwise the sharing check has nothing to read.
Good to know
A client tenant without Microsoft Entra ID P1 or P2 cannot answer the sign-in and risk questions at all. Avvi says so explicitly and names what can still be checked: message trace, inbox rules, forwarding, mailbox permissions, directory audit logs, and connectors.
Tenant-wide questions are separate requests. Scanning every sign-in across a client, or listing everybody currently flagged as risky, does not need a named person.
Verify it worked
Confirm the report names the person you meant and the client you expect.
Confirm you can see, for each check, whether it completed. If the answer relies on a check that was skipped, the answer is weaker than it looks.
If something doesn’t look right
If most checks were skipped, look at the client’s Microsoft licensing before concluding anything about the account. P1 or P2 is what those checks need.
If a check failed rather than being skipped, that is a permissions problem and the consent page covers it.
If the report is clean and the symptom persists, widen to the tenant. A single account can look fine while another is the source.
If you need to escalate, open a support conversation from the Help drawer. Include the client, the person, what the symptom was, and which checks were skipped.
FAQ
Q: Does this change anything?
A: Nothing about the person. The first run may switch on SharePoint audit collection for the client tenant.
Q: Can I check the whole client at once?
A: Yes, as a separate request. A tenant-wide scan does not need a named person.
Q: The report says a check was skipped. Is that bad?
A: It means unknown, not clean. The usual cause is the client’s Microsoft licensing.