All sites covered by the Overe Protect plan have access to threat response features, enabling swift action to mitigate potential security incidents and prevent further impact.
Response actions
We are currently implementing two key actions to mitigate potential security incidents:
Revoke User Session: This action immediately terminates the Microsoft session associated with the affected account, preventing any further activity by a potentially malicious actor.
Block User Account: To prevent unauthorized reaccess, Overe enforces a Conditional Access policy that blocks the compromised account from logging into any Microsoft system. This measure gives administrators time to investigate the incident and implement necessary security steps to protect the system.
The Conditional Access policy managing blocked accounts is listed in Entra as "(Overe) Block Users".
Licensing note.
Because this action works through a Conditional Access policy, the blocked user must hold a licence that includes Conditional Access â Microsoft 365 Business Premium, M365 E3/E5, or an Entra ID P1 add-on. Blocking a user who does not hold one of these will take effect technically, but places the tenant outside Microsoftâs licensing terms for as long as that user remains in the policy.
This matters most in mixed-licensing tenants. If some of your users are on Business Standard or another SKU without Conditional Access rights, review your response configuration before enabling automated actions against them. Revoking sessions is not affected and can be used for any user.
See Third-party licensing and policy scope for where this responsibility sits and what to check.
These response actions are available in the User Details Panel within the Users Section and can also be accessed in the context of a potential incident through the Alert Details Panel.
Automated Response
While the features outlined above require manual action, you can also configure automated responses to handle incidents instantly without human intervention. To learn how to set up these triggers, see the Automated Response section.
Automated Response acts without an administrator present, so licence eligibility is not reviewed at the point of action. Before enabling automatic account blocks, confirm that the users in scope are appropriately licensed for Conditional Access, or restrict the automationâs scope accordingly. Where a user is not eligible, session revocation and alert-only responses remain available. See Third-party licensing and policy scope for more detail.

