# RAIDEN ## Docs - [What is RAIDEN? M365 threat detection and response](https://docs.raidenhq.com/introduction.md): RAIDEN monitors your M365 tenant for threats, groups findings into AI-investigated cases, and lets you respond in one click — no security team required. - [Get started with RAIDEN: connect M365 in 15 minutes](https://docs.raidenhq.com/getting-started.md): Connect your Microsoft 365 tenant to RAIDEN and see your first threat detections in under 15 minutes — no security expertise required. - [RAIDEN hybrid AD onboarding: connect and monitor AD-synced M365 tenants](https://docs.raidenhq.com/hybrid-ad-onboarding.md): Set up RAIDEN for environments where on-premises Active Directory is synced to Microsoft 365 via Azure AD Connect (Entra Connect). Covers prerequisites, monitoring scope, and remediation limitations for AD-synced accounts. - [Microsoft permissions RAIDEN requests](https://docs.raidenhq.com/permissions.md): The exact Microsoft Graph, Microsoft Defender for Endpoint, and Office 365 Management API permissions RAIDEN asks for during onboarding — what each one is for, and which are read-only versus used for response actions. - [Get started as an MSSP partner](https://docs.raidenhq.com/mssp-getting-started.md): Create your MSSP management account, add customer tenants, and connect their Microsoft 365 environments. Complete setup takes about 10 minutes. - [Cases and alerts in RAIDEN: triage and investigation](https://docs.raidenhq.com/cases-and-alerts.md): Learn how RAIDEN groups individual detections into investigation cases and how to triage, investigate, and close threats effectively. - [Monitored users](https://docs.raidenhq.com/monitoring-users.md): How RAIDEN identifies and monitors Microsoft 365 users — automatic detection, manual add, and managing your user list. - [Identity Threat Detection & Response (ITDR)](https://docs.raidenhq.com/itdr.md): How RAIDEN automatically investigates Entra ID risky users and Microsoft Defender identity alerts, and how to review and act on them. - [RAIDEN response actions: contain threats from the case view](https://docs.raidenhq.com/response-actions.md): Understand the write operations available in RAIDEN — what each action does, which permission it uses, and how to trigger it from the case view. - [Manage your RAIDEN team: roles, invites, and access](https://docs.raidenhq.com/team-management.md): Add team members, assign the right role for each person's responsibilities, manage pending invites, and change roles as your team evolves. - [RAIDEN alert notifications: who gets them and when](https://docs.raidenhq.com/notifications.md): Find out which events trigger email notifications, who receives them by default, and how to adjust notification settings for your team. - [Send feedback to the RAIDEN team](https://docs.raidenhq.com/send-feedback.md): Report bugs, suggest features, ask questions, or share general feedback directly from RAIDEN. - [RAIDEN detection coverage: M365 threat detections](https://docs.raidenhq.com/detection-coverage.md): What RAIDEN detects across Microsoft 365 — identity and AiTM, business email compromise, OAuth consent abuse, device-code phishing, Teams abuse, Defender endpoint signals, and data exfiltration. - [What's new in RAIDEN](https://docs.raidenhq.com/whats-new.md): Latest updates, new features, and improvements to the RAIDEN platform. - [RAIDEN frequently asked questions: setup and detections](https://docs.raidenhq.com/faq.md): Answers to common questions about connecting Microsoft 365, understanding detections, managing team access, and getting help from RAIDEN support. - [RAIDEN troubleshooting: connections, detections, and access](https://docs.raidenhq.com/troubleshooting.md): Step-by-step fixes for common RAIDEN issues — Microsoft 365 connection failures, missing detections, invite problems, and how to reach support. ## OpenAPI Specs - [openapi](https://docs.raidenhq.com/api-reference/openapi.json)