Skip to content

Introduction to Compliance Controls

Microsoft Entra ID Application

Monitoring Microsoft Entra ID events provides critical visibility into user identities, authentication activity, and access management across cloud and hybrid environments. By continuously monitoring identity-related events, organisations can strengthen security, improve operational efficiency, and meet compliance requirements.

**Strengthening Identity Security ** Monitoring Microsoft Entra ID events helps identify potential security threats, including suspicious sign-in activity, impossible travel events, privilege escalation attempts, account compromise, and unauthorised modifications to users, groups, roles, or applications. Early detection of these events enables security teams to investigate and respond to identity-based threats before they impact the organisation.

Enhanced Threat Detection and Response As part of Crystal Eye XDR, Microsoft Entra ID telemetry can be correlated with endpoint, network, cloud, and security event data to provide broader visibility into attack activity. This enables faster detection of sophisticated threats, improved investigation capabilities, and more effective incident response.

Troubleshooting and Operational Visibility Monitoring identity events helps administrators diagnose and resolve user access issues, authentication failures, conditional access policy conflicts, and application integration problems. Detailed audit and sign-in logs provide valuable insights into the health and operation of identity services across the organisation. ** Auditing and Compliance ** Many regulatory frameworks and compliance standards require organisations to maintain audit trails of identity and access management activities. Monitoring Microsoft Entra ID events provides comprehensive records of user actions, administrative changes, authentication attempts, and access requests, supporting governance, risk management, and compliance initiatives.

Improved Access Governance Visibility into identity activities helps organisations maintain effective access controls, review privileged accounts, monitor role assignments, and detect unauthorised changes. This supports the principle of least privilege and improves overall identity governance.

Overall, monitoring Microsoft Entra ID events provides valuable insight into identity-related activities across the organisation, helping security teams strengthen cyber resilience, improve threat detection, support compliance requirements, and maintain a secure and efficient identity infrastructure.

Data Loss Protection


The Data Loss Protection application allows organizations to boost their DLP program designed to provide protection from getting breach.

The DLP app is utilized by DLP program implementers to reduce risks derived from poor business processes. The overall features of the DLP app works as an excellent tool to help organizations comply with ISO 27002:2022 framework, Control 8.12 – Data Leakage Prevention.

An effective DLP program must be built in-line with the controls put in place to classify information based on confidentiality, integrity and availability.

Crystal Eye XDRs DLP application policies can be configured to both Reject and Alert mode providing control over the movement of sensitive data that have been labeled to be protected against exfiltration.

Once the DLP feature is enabled it searches all files located in various computers in the CE network for structured data formats involving credit card numbers and social security numbers (SSN). Thereon, the DLP apps in-built default functionality triggers an alert every time Credit Card Numbers and Social Security Numbers (SSN) are extruded outside CE XDR networks.

PCAP SNAP Application


The PCAP Snap app is used to capture network traffic and then transfer it to designated Red Piranha servers for automatic analysis and manual examination. The most convenient aspect of using this application is that it has a phenomenal packet capture scheduler that can be used to add multiple schedules as per requirements.

Running PCAP analysis is done in conjunction with our Security Operations Team during either a breach investigation process or a compliance threat hunting process.

Crystal Eye Attack Surface Reduction (CESAR) Application


The Crystal Eye Attack Surface Reduction (CEASR) application ensures devices on your network conform to security policies based on standard security frameworks such as the Australian Signals Directorate's Information Security Manual (ISM) and the Essential Eight guidelines. It also allows CE XDR administrators to apply operating system policies across a range of devices and provide ongoing device monitoring to keep track of your compliance baseline in real-time.

Vulnerability Scanning


The Vulnerability Scanning application is a comprehensive vulnerability assessment system that is built to detect, and flag known and potential security weaknesses in servers and user devices located in the Crystal Eye network or elsewhere.

The application has enhanced capabilities to perform vulnerability scan of:

  • Servers and user devices in the Crystal Eye network,
  • Servers or user devices located outside the Crystal Eye network, or
  • Specific website page

The application is programmed to scan all default port types. However, the Crystal Eye administrator can also specify the custom ports to be scanned. The fully automated system of the Vulnerability scanning application enables CE administrators to identify security loopholes in the network and classify weaknesses that might lead to a security incident. It helps in predicting the effectiveness of the various countermeasures taken to secure networks and assists in remediating any risks that are targeted towards external facing servers deployed in the Crystal Eye network.