Skip to main content
Find answers to the most common questions about setting up RAIDEN, understanding detections and cases, and managing your team. If your question isn’t covered here, contact support at support@raidenhq.com.

Setup & Connection

Yes, this is expected. RAIDEN is in early access and Microsoft publisher verification is in progress. The warning does not indicate a security risk. Click Accept to continue with the consent flow.
RAIDEN connects to two separate Microsoft APIs — Microsoft Graph and the Office Management Activity API. Microsoft requires a separate consent screen for each. Both use the same Global Administrator account and the whole process takes under 30 seconds.
No. RAIDEN works at any Microsoft 365 licence tier. It uses the Office Management Activity API for audit log ingestion, which is available across all commercial M365 plans.
The most common causes are:
  • Audit logging not enabled — go to Microsoft Purview → Audit → Start recording user and admin activity
  • Insufficient privileges — the consenting account must be a Global Administrator
  • Second consent not completed — go to Settings → Connection and click Reconnect M365
If none of these apply, email support@raidenhq.com with your tenant slug and the error shown in Settings → Connection.
Check your junk or spam folder first — invite emails are occasionally filtered by corporate mail systems. If it’s not there, contact your RAIDEN onboarding contact to resend the invite.

Detections & Cases

Filter by Critical and High severity first. Work Cases, not individual alerts — the case report gives you the full picture with an AI-generated investigation summary. Individual alerts are the building blocks; cases are the investigations.
Mark the alert as False Positive and use the suppression options to prevent future alerts for the same IP, application, or user. RAIDEN will not fire that rule against that entity again.
Go to Settings → Connection to see the last poll time and event count. If no events have been ingested in the last 30 minutes, check the connection status. You can also email support@raidenhq.com if you suspect a connectivity issue.
RAIDEN starts polling immediately after the connection is verified. The first poll processes the last 24 hours of audit logs. Findings typically appear within 5–10 minutes depending on your tenant activity level.

Team & Access

RoleWhat they can do
OwnerFull access — team management, M365 connection, all settings
AdminFull access except owner-only settings — can invite users and change roles
AnalystView and action cases and alerts, mark false positives, export reports
ViewerRead-only access to cases and alerts

Still need help?

Email support@raidenhq.com with your organisation name or tenant slug and a brief description of the issue. For active compromise situations, include URGENT in the subject line to ensure your request is prioritised.