> ## Documentation Index
> Fetch the complete documentation index at: https://docs.raidenhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# RAIDEN: M365 threat detection and response platform

> RAIDEN monitors your Microsoft 365 environment for threats, generates AI-powered investigations, and lets you respond directly from one dashboard.

RAIDEN connects to your Microsoft 365 tenant to detect account compromises, suspicious logins, and insider threats in real time. Every detection is automatically grouped into an investigation case with an AI-generated summary, so your team can triage fast and respond directly — without switching between admin portals.

<CardGroup cols={2}>
  <Card title="Quick Start" icon="rocket" href="/getting-started">
    Connect your M365 tenant and see your first detections in under 15 minutes.
  </Card>

  <Card title="MSSP Partner Setup" icon="building" href="/mssp-getting-started">
    Create your MSSP account, add customers, and manage their tenants from one dashboard.
  </Card>

  <Card title="Cases & Alerts" icon="shield-halved" href="/cases-and-alerts">
    Understand how RAIDEN groups detections into investigations.
  </Card>

  <Card title="Response Actions" icon="bolt" href="/response-actions">
    Revoke sessions, disable accounts, and block threats without leaving RAIDEN.
  </Card>

  <Card title="Identity Threat Detection" icon="user-shield" href="/itdr">
    Auto-investigate Entra ID risky users and Microsoft Defender identity alerts.
  </Card>

  <Card title="Permissions" icon="lock" href="/permissions">
    See exactly what RAIDEN requests access to in your M365 tenant and why.
  </Card>
</CardGroup>

## How RAIDEN works

<Steps>
  <Step title="Connect Microsoft 365">
    Grant RAIDEN read access to your M365 audit logs and security signals via a guided admin consent flow. Takes under 2 minutes.
  </Step>

  <Step title="Detections start immediately">
    RAIDEN polls your audit log continuously. The first run processes the last 24 hours. Findings typically appear within 5–10 minutes.
  </Step>

  <Step title="Review cases">
    Detections are grouped into Cases. Each case includes an AI-generated investigation report — read that first before diving into individual alerts.
  </Step>

  <Step title="Respond in one click">
    Use Response Actions to revoke sessions, disable a compromised account, or create a Conditional Access block policy directly from the case view.
  </Step>
</Steps>

<Note>
  RAIDEN is currently in **early access**. Features are fully functional — if you hit anything unexpected, email [support@raidenhq.com](mailto:support@raidenhq.com) or contact your RAIDEN onboarding contact directly.
</Note>
