The treasurer's SaaS mailbox shows impossible-travel sign-ins. Which source is most useful for that account-takeover analysis?
Select an answer to reveal the explanation.
Short Explanation
Impossible travel on a cloud mailbox is an identity story. Entra (Azure AD) sign-in logs saw the token; the city firewall, the pump historian, and the office badge reader did not.
Full Explanation
SaaS account-takeover and impossible-travel analysis depend on cloud identity telemetry—Azure AD / Entra sign-in logs that include user, app, IP, location, and result. An on-prem perimeter firewall does not enumerate SaaS token claims, OT historian values are unrelated, and physical badge events do not complete Entra MFA or replace sign-in logs. For a municipal treasurer mailbox, pull the cloud identity source first, then correlate with mailbox audit if needed.