Request pilot access
Product Security About Contact Request pilot access

Product

Five screens, one investigation.

HawkView reads the records your customers’ Microsoft 365 tenants already keep. Here is what each screen is for, and what it will and will not tell you.

Dashboard · Priority Action Queue

Start with a shortlist.

Every row names the tenant it came from, how severe it is, and how long it has been sitting there. Filter by customer or severity without leaving the page.

The queue mixes what HawkView could not read with what it did: lost connections and missing permissions, collectors that failed or went stale, MFA registration coverage below 85%, Microsoft’s own risk counts, and up to three directory-audit changes from the last 24 hours — conditional access and named locations, authentication methods, applications and service principals, and administrative roles.

The priority action queue: four items ordered by severity, each naming the tenant, the account or policy affected, how long ago it was recorded, and an action to investigate it The priority action queue: four items ordered by severity, each naming the tenant, the account or policy affected, how long ago it was recorded, and an action to investigate it

Dashboard · Tenant Risk Matrix

Compare customers, gaps included.

Secure score, identity, data and app coverage in one grid. Where a score needs a permission that has not been granted, the cell says so rather than showing a low number.

A tenant whose licensing does not provide a score reads Not available, not zero. The two are different facts and the grid keeps them apart.

The tenant risk matrix comparing four customers, with one tenant reading Not available because licensing or the API did not provide a score The tenant risk matrix comparing four customers, with one tenant reading Not available because licensing or the API did not provide a score

What Changed?

Reconstruct the hour around an incident.

A cross-customer view of administrative change — conditional access, roles, applications, groups, licences and mailbox rules — classified by type and severity, grouped by day, with the window you are looking at always stated.

The What Changed screen: the page title and filters above a timeline of administrative events grouped by day, with a mailbox forwarding rule creation among them The What Changed screen: the page title and filters above a timeline of administrative events grouped by day, with a mailbox forwarding rule creation among them Mailbox forwarding rule created

Events are classified by type and severity and grouped by day. This is a curated view rather than a raw feed — supporting evidence is demoted rather than hidden, so you can still see it and still see what it is.

Two screenshots of the real application. Selecting the event in HawkView opens the panel shown in step two.


Activity Logs

One customer, the underlying records.

Where What Changed looks across every customer and interprets, Activity Logs goes the other way: pick one tenant and read its Microsoft records as Microsoft supplied them.

The Activity Logs sign-in table for one customer: date, user, application, status, conditional access, IP address and location on each row The Activity Logs sign-in table for one customer: date, user, application, status, conditional access, IP address and location on each row

Date, user, application, status, conditional access, IP address and location. Where a sign-in came from the audit fallback rather than Graph, the thinner record shows in the row itself — conditional access, IP address and location each read Not reported rather than sitting empty.

Filter by tenant, user, free text and a date range of 7 to 180 days, or a custom window. Narrow further by status, conditional access, application, location, IP, client, operating system or risk level — with the options drawn from the data actually present. Export the filtered set to CSV. HawkView does not acknowledge, assign or annotate; it reads.


Identity investigation · pilot

An investigation lead, with its evidence attached.

Identity investigation is the newest part of HawkView and is not switched on by default. Where it is enabled for a tenant, it reviews the sign-in records that tenant already keeps and surfaces accounts worth a look — repeated invalid-credential attempts, and accounts Microsoft locked out after them — naming the person, counting the events and saying when it last saw one.

Ask us whether it is enabled for your pilot. Where it is not, the page says so rather than showing a clear result.

HawkView’s own rule findings and Microsoft Entra ID Protection detections are kept as independent sources and are never combined into a single score. A finding is a reason to look, not a finding of compromise — and the account changes themselves are made in Microsoft’s own tools, not here.

An identity finding opened for a named user: why the user needs review, an account lockout following failed sign-ins, a note that the Microsoft risk comparison is incomplete, and two findings with their event counts An identity finding opened for a named user: why the user needs review, an account lockout following failed sign-ins, a note that the Microsoft risk comparison is incomplete, and two findings with their event counts

Coverage and freshness

An empty panel should tell you why it is empty.

A clear result means no rule matched inside the evidence HawkView could read, over the window stated on the page. It does not mean the customer is safe.

NOT LICENSEDMicrosoft gates this dataset behind a premium plan.
PERMISSION BLOCKEDA permission has not been granted, so the dataset cannot be read.
STALEThe last successful collection is older than the freshness threshold.
PARTIALSome of the dataset was read and some was not.
NEVER COLLECTEDHawkView has not yet succeeded here.
A dashboard in which unreported values remain visibly unavailable, with one tenant’s cells reading Not available and Not reported rather than zero A dashboard in which unreported values remain visibly unavailable, with one tenant’s cells reading Not available and Not reported rather than zero

Microsoft’s audit content is asynchronous and can arrive hours late and out of order. HawkView polls on a schedule and stamps every panel with when it last collected successfully — it is a record you can reconstruct from, not a real-time alarm. What that means in practice →

See it against your own customers.

A pilot connection is read-only and revocable at any time. Start with one tenant and judge it on a customer you already know well.