Security Operations
Help Centre
❓
What is ProPera Online?

A Microsoft security automation & AI security operations platform. It connects to Defender for Endpoint, XDR, Sentinel, Intune, Purview, Secure Score and Graph, and adds threat intelligence, MITRE ATT&CK mapping, risk scoring, AI investigation, approval-gated remediation, a full response pipeline and continuous compliance monitoring.

How do I connect my Microsoft tenant?

Open the Configuration Centre (or Settings β†’ Tenant for per-workspace credentials), enter your tenant ID, client ID and client secret (or certificate / managed identity), save, then click Test Connection. Green = connected. See Integrations & SSO for the full walkthrough.

How do I enable Sign in with Microsoft or Google?

Both use OAuth 2.0 + PKCE. For Microsoft, register an app in Entra ID with redirect URI /auth/entra/callback, enable Allow public client flows, and set ENTRA_SSO_ENABLED, AZURE_TENANT_ID and AZURE_CLIENT_ID. For Google, create an OAuth client (Web application) with redirect URI /auth/google/callback and set GOOGLE_SSO_ENABLED, GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET. Full instructions: Integrations & SSO.

Why is an integration showing orange / Configuration required?

It means the integration is required by your subscription but credentials are not set, or a saved credential is not yet verified. Open the Configuration Centre, enter the details and use Test Connection. Red (Connection failed) means the provider rejected the request - check the reason shown and fix the credential.

Can ProPera change the registry or run destructive actions?

No. ProPera Online never writes the registry. Registry-related fixes are always denied and escalated to an Administrator, with a warning popup explaining why. Destructive actions (isolation, blocking) are approval-gated and never automatic by default. Updates-only fixes are queued via patch management and always notify you.

Why was my auto-remediation blocked?

Either the action requires a registry change (denied + escalated to an Administrator) or your role cannot execute remediation. The popup tells you the exact reason. Administrators can execute non-registry actions; non-admins see their role's limitation with a clear message.

What does the Response Pipeline do?

It runs the full detect β†’ enrich β†’ MITRE map β†’ risk (CVSS/EPSS + exposure) β†’ CIS/NIST controls β†’ isolate β†’ investigate β†’ remediate β†’ verify β†’ Secure Score β†’ audit/report chain per incident, with a visual stage-by-stage status you can advance.

How does the AI Security Analyst work?

It analyses real evidence (alerts, devices, users, MITRE techniques) to produce attack narratives, risk scores and recommended responses with honest confidence levels. It never claims malicious activity without proof, and it can draft KQL queries for Advanced Hunting from a plain-language prompt.

What compliance frameworks are supported?

Continuous control monitoring for ISO 27001, NIST CSF 2.0, CIS Controls v8 and the Essential Eight, plus geo-aware frameworks (NZISM for New Zealand, IRAP for Australia, GDPR for the EU and more). Only frameworks that apply to your location and industry profile are evaluated.

Where can I see what changed in the environment?

Every approval request shows what will change (action, device, method, risk, MITRE technique), and decided approvals show the before β†’ after diff. The System Logs page records every user action, security action, approval decision and configuration change, searchable and exportable.

Is there a demo I can try?

Yes - the Demo site runs the full product with realistic sample data and no Microsoft tenant needed. Perfect for evaluating the platform before connecting your environment.

How do I get support?

Use the help centre, the πŸ€– AI Guided Tour, or email info@propera.online. The Unlimited plan includes dedicated support.