The dashboard is the starting point for daily tenant operations. It summarizes current protection, investigations, and service health without replacing the detailed workflows in Detect, Protect, or Respond.

Summary cards

  • Messages scanned shows recent message-processing volume.
  • Threat detections separates malicious and suspicious results.
  • Open incidents counts investigations requiring attention.
  • Protected mailboxes reflects the current Microsoft 365 scope.
  • Defender reports shows recent user-reported evidence when Defender is connected.
  • Microsoft quarantine shows pending provider-reported actions where supported.
  • DMARC alignment summarizes authentication reporting for the selected period.

Detection trend

The 14-day trend groups message decisions by day. Hover or focus a bar to read the clean, suspicious, and malicious counts. A missing trend does not necessarily indicate a problem; it may mean telemetry has not arrived or the tenant does not have ICES coverage.

Priority Queue

The queue links to incidents, posture findings, and service failures that need attention. Work from the queue to the detailed page so the relevant evidence and permission checks are preserved.

Operational rhythm: Start with the Priority Queue, open the related detail, record or complete the action, then review the Audit Trail for configuration and response changes.

Empty and unavailable states

“No data yet” means the source is connected but has not produced records. “Unavailable” means a provider, module, or assessment is not ready. Follow the action link in the card instead of repeatedly refreshing an unconfigured integration.