Behavioral Identity
Threat Detection
Microsoft identifies identity risk. AuthLokr extends that detection with tenant-specific behavioral baselines, post-authentication activity correlation, and explainable risk scoring.
A complementary layer for Microsoft 365 environments — surfacing insider risk, session anomalies, and attack-chain correlations that benefit from tenant-specific behavioral context.
- ✓Microsoft-native
- ✓Agentless
- ✓Read-only by default
- ✓Explainable AI
- ✓Designed to deploy in under an hour
Impossible travel + unfamiliar device
alice.anderson@company.com
Finance · Global Admin · Baseline: 94 days
Location baseline for this user is Denver metro (98% of sign-ins, 90 days). Combined with a first-seen device and off-pattern time window, the correlated risk exceeds the compromise threshold.
Become part of AuthLokr's founding customer cohort
A limited-time offer for the first 5 qualifying organizations. Locked founding economics in exchange for reference rights and quarterly roadmap input. Applications close September 30, 2026.
- 24-month price lock at $7.20/user/month (20–40% below market rate)
- Perpetual 10% discount forever after the 24-month lock — price protection for life
- Reference rights included (become a case study, help us close future deals)
- Quarterly roadmap input — you influence what gets built next
- $15–25K pilot fee credited toward your first month of subscription
- Direct engineering access, not just support
Authentication succeeded. Is the identity still behaving like itself?
Microsoft Entra ID Protection and SIEM tooling identify identity risk at sign-in and across audit streams. AuthLokr adds a complementary layer: tenant-specific behavioral baselines and post-authentication correlation that helps surface insider risk, session anomalies, and attack chains with analyst-friendly, explainable reasoning.
- Insider and post-auth activity benefits from user-level behavioral context.
- Tenant-specific baselines complement native, global risk models.
- Correlating sign-in, role, session, and data events shortens investigations.
Global identity risk model with strong sign-in and audit signals.
Adds tenant-specific behavioral baselines per user across 6 dimensions.
Rich individual events across sign-in, role changes, and audit logs.
Correlates those events into explainable attack-chain narratives.
Baselines per user. Correlation across every dimension.
Every alert includes plain-English reasoning. You see why a score was assigned — not just a number.
Location Intelligence
Is this location normal for THIS user? Detects impossible travel and unusual geography.
- Sign-in from Russia 4h after Denver login
- First-time country access for a non-traveling role
Temporal Patterns
Does this match when this person normally authenticates?
- Global Admin accessing systems at 02:00
- Weekend privileged role activation for a M–F role
Device Fingerprinting
Does this user normally use this device/OS/browser combination?
- macOS Safari sign-in on a Windows-only baseline
- Unfamiliar TLS fingerprint on a corporate identity
Access Patterns
Does this user typically touch this resource?
- Finance user accessing patient records for the first time
- Engineer opening 42 SharePoint sites never touched in 90 days
Volume Analysis
Is this volume of activity normal for this user?
- 10× normal file download volume before resignation
- Bulk mailbox export at off-hours
Account State Monitoring
Detects privilege escalation, MFA tampering, and backdoor authentication.
- Risky sign-in + Global Admin role granted + suspicious activity
- MFA method changed inside a scored session
Session Hijacking Detection
Real-time mid-session IP and user-agent monitoring. Blocks continuation on suspicious transitions.
Privilege Escalation Correlation
Ties risky sign-ins to role grants and downstream access — one attack chain, not three isolated events.
AiTM / MitM Indicators
Session trust degradation, network-path anomalies, and browser stack deviation.
Detection in motion
Three real-world attack patterns, scored against tenant-specific behavioral baselines.
Impossible Travel Detection
- 109:14 — Login from Denver, CO (trusted device, baseline match)
- 210:22 — Login from Moscow, RU (unrecognized device)
- 3Δ 68 minutes — 5,400 miles — physically impossible
P2 flags atypical travel against generic global thresholds. AuthLokr scores it against this user's own 30-day movement baseline.
- IMPOSSIBLE TRAVEL — 5,400 miles in 68 minutes
- UNRECOGNIZED DEVICE FINGERPRINT
- BASELINE DEVIATION — 4.7σ from user's normal geography
How it works
Three phases. No production changes required. Detection starts on day 31.
1. Connect your tenant
Read-only Microsoft Graph API access via OAuth 2.0 for the monitoring platform. Agentless. No production changes. Designed to deploy in under an hour.
2. SanctumOS AI learns baselines
30-day silent learning window per user: location, temporal, device, resource, volume, and account-state patterns — tenant-specific, not a global model.
3. Detect, score, respond
Real-time alerts with explainable AI reasoning. Optional response actions (revoke session, require MFA, disable account) require separately approved delegated permissions.
Why AuthLokr + P2 beats P2 alone
Microsoft Entra ID P2 is strong at identifying known identity risk signals. AuthLokr adds the tenant-specific behavioral context, session-level detection, and attack-chain correlation that sits on top of it.
| Capability | Entra ID P2 alone | AuthLokr + P2 |
|---|---|---|
| Impossible travel detection | Generic global thresholds | Per-user behavioral baselines learned from your tenant |
| Session hijacking detection | Limited | Mid-session IP, device, and token anomaly detection |
| Privilege escalation correlation | Not correlated with sign-in risk | Audit log + sign-in correlation for full attack chains |
| Insider threat detection | Focused on external compromise | Behavioral deviation from each user's own normal |
| Custom behavioral baselines | Tenant-wide heuristics | 30-day learning period per organization and per identity |
| Attack chain visibility | Event-by-event | Multi-event temporal correlation and timeline view |
| Risk score transparency | Opaque risk levels | Explainable scoring with tunable LOW/MED/HIGH/CRITICAL thresholds |
AuthLokr is designed to complement Microsoft Entra — not replace it. Capability descriptions reflect typical customer deployments; exact P2 behavior varies by licensing and configuration.
Making a Microsoft licensing decision this quarter?
P1 → P2 upgrades. P2 annual renewals. E5 cost reviews. Each is a chance to evaluate how a behavioral analytics layer fits alongside your Microsoft identity stack — before the next 12-month commitment.
Before you upgrade, see how AuthLokr complements native detection with tenant-specific baselines and explainable post-auth correlation.
Renewing P2? A 30-day AuthLokr pilot can layer behavioral baselines and attack-chain analytics on top of your existing Entra investment.
Reviewing E5 spend? AuthLokr can help identify where behavioral analytics reduce reliance on higher-tier bundles — potentially lowering unnecessary licensing costs.
Pricing model
Flat-fee tiers for organizations with 2,500+ users. Per-user pricing below 2,500. Published rates — no "contact us" black box.
Growth
- Custom behavioral baselines
- Real-time monitoring
- Privileged role approval workflows
- Email support
Scale
- Everything in Growth
- Advanced dashboards
- Alert tuning
- Audit logging
Enterprise
- Full suite
- Dedicated support
- 24/7 response
- Custom integrations
Consistently 20% below Microsoft Entra ID P2 list pricing of $10/user/month.
All tiers. After the 24-month lock, founding customers keep a permanent 10% discount off the then-current rate.
What's included (all tiers)
- Custom behavioral baselines (30-day learning period per organization)
- Real-time session monitoring (session hijacking, token replay, impossible travel)
- Privilege escalation correlation (audit log + sign-in correlation for attack chains)
- Multi-event temporal correlation (attack chain visibility)
- Transparent risk scoring (LOW / MEDIUM / HIGH / CRITICAL — tunable thresholds)
- Privileged access approval workflows (block privileged access on HIGH risk events)
- Real-time alerts dashboard
- Attack timeline visualization
- Monthly executive summary reports
- Email support (business hours, 24-hour response SLA)
- Self-service deployment (documentation portal, 2-hour kickoff call)
Optional add-ons
Professional Support
- Priority email + phone support (business hours)
- 4-hour response SLA for critical issues
- Quarterly business reviews (QBR)
- Direct Slack channel with the support team
- Custom detection rule setup (3 rules included)
- Integration assistance (1 integration)
- Quarterly risk posture reports
Enterprise Support
- 24/7 phone + email support
- 1-hour response SLA for critical issues
- Dedicated Customer Success Manager (CSM)
- Private Slack channel with the engineering team
- Monthly strategic check-ins
- Unlimited custom detection rules
- Unlimited integrations
- Bi-weekly detection tuning sessions
- SOC workflow optimization consulting
- Incident response assistance (up to 10 hours/quarter)
- Post-incident analysis and recommendations
- Monthly threat hunting support
30 days baseline learning + 30 days live detection. Credited dollar-for-dollar toward your first month(s) of subscription on conversion.
What the Founding Customer Program actually is
AuthLokr is early, deliberately. We are taking on 5 founding customers and no more before September 30, 2026. Founding customers get economics and influence that will never be offered again — in exchange for being publicly referenceable and genuinely engaged. It is a two-way commitment, not a discount code.
24-month price lock
$7.20/user/month, or the discounted flat-fee equivalent for your tier. No mid-term increases, regardless of published pricing changes.
Perpetual 10% discount
After the 24-month lock expires, founding customers keep a permanent 10% discount off the then-current rate. Price protection for life.
Quarterly roadmap input
A standing call with the founding cohort where we walk the roadmap, take your prioritization input, and commit to what ships next.
Direct engineering access
Not a support queue. Founding customers work directly with the engineers building the detection logic.
- · Reference rights: participate in a case study, testimonial, and periodic reference calls with prospects.
- · Deploy in production within 60 days of signature so baselines have real data to learn from.
- · Attend the quarterly roadmap call and give candid feedback on detections and false positives.
Pilot path: a $15–25K, ~60-day paid pilot rolls straight into a founding slot at conversion, with the pilot fee credited toward your first month(s) of subscription.
Regulated, understaffed, high-risk.
AuthLokr is tuned for mid-market Microsoft 365 environments (2,500–50,000 users) where a small security team owns a large blast radius.
Healthcare
Designed to support HIPAA-regulated environments. Insider-risk analytics tuned for patient-record access patterns, off-hours activity, and departing-employee risk windows.
Defense & CMMC
Designed to support CMMC-aligned deployments (Level 2/3 objectives). CUI access monitoring and behavioral correlation. Air-gap capable (Phase 3 roadmap).
Financial Services
SOX-aligned audit trails, fraud-pattern analytics, and privileged-user behavioral scoring for trading, treasury, and admin roles.
Built for regulated environments.
Patent pending
Behavioral threat detection methodology patent filed Q3 2026.
SOC 2 Type II
Roadmap objective. Targeted for Q4 2026; not yet certified.
HIPAA-ready
Designed to support HIPAA-regulated environments. Read-only audit-log access. No PHI stored.
CMMC-aligned
Designed to support CMMC-aligned deployments (Level 2/3 objectives). Air-gap capable on Phase 3 roadmap.
Data privacy
Customer data stored in customer region. No external telemetry.
Least-privilege access
Core monitoring uses read-only Microsoft Graph scopes via OAuth 2.0. Optional response actions require separately approved delegated permissions.
Ready to see what your baselines look like?
Start with a Founding Program application or a scoped demo. No auto-scheduler — John reads every submission personally and reaches out to book time that works.
About BlackCert Labs

BlackCert Labs was founded by engineers and architects who spent years implementing, securing, integrating, and responding inside real enterprise environments — not building marketing demos. Our work has spanned Fortune 500 enterprises, government, critical infrastructure, financial services, and healthcare — across Microsoft cloud, enterprise identity, Zero Trust programs, incident response, threat hunting, compliance, AI security, blockchain and cryptocurrency security, cloud architecture, and enterprise modernization.
After deploying nearly every major security platform available, one pattern became obvious: traditional products generate enormous amounts of alerts and telemetry, yet security teams still spend too much time determining whether authenticated users can actually be trusted. BlackCert Labs exists to close that gap.
AuthLokr was created because this problem appeared repeatedly during real customer engagements — not because it looked interesting on a whiteboard. BlackCert builds the products the team wished they had while defending production environments: focused, explainable, and useful in the middle of an incident.
BlackCert Labs builds security software for organizations that demand practical answers, explainable intelligence, and technology that earns trust in production — not just in demonstrations.
