Early access — You are using an early access build of RAIDEN. Features are fully functional but some UI polish is still being completed. If you hit anything unexpected, contact your RAIDEN onboarding contact directly.
Before you start
You will need:- RAIDEN MSSP partner code — provided during your partner onboarding. Contact [email protected] to apply
- Customer information — organisation names and billing email addresses for each customer you want to add
- Microsoft 365 Global Admin access (per customer) — needed when connecting each customer’s M365 tenant. This can be done by the customer themselves or by you on their behalf
Setup steps
1
Create your MSSP account
- Navigate to https://account.raidenhq.com/signup/mssp
- Fill in the MSSP signup form:
- Full name — Your name
- Business email — Your work email (becomes your MSSP admin login)
- Password — Minimum 8 characters
- MSSP organisation name — Your MSP’s company name. RAIDEN uses this to create your management subdomain (e.g.
secureco.raidenhq.com) - MSSP partner code — The code provided to you
- Click Create MSSP account
2
Add your customers (Onboarding Wizard)
The onboarding wizard is a three-step flow that helps you set up your MSSP account and add your first customers. You can skip it at any time using the “Skip to Dashboard” button.Step 2a — WelcomeA quick orientation explaining what RAIDEN MSSP provides:Rules:
- Centralised dashboard to monitor all customer tenants
- One-click impersonation to investigate threats in any customer’s environment
- Health summary across your entire customer portfolio
- Enter the Organisation name (required), Billing email (required), and optional Alias (a short internal nickname)
- Click the + button to add another row
- Repeat for each customer
- Click Submit & Review when ready
- Comma-separated or tab-separated
- Header row is optional (lines starting with “organization” are skipped)
- Alias column is optional
- Up to 50 customers per batch
- Successfully created — Each customer with a “Copy Invite Link” button. Share this link with your customer so they can sign up and connect their M365 tenant.
- Failed — Any items that could not be created (e.g. duplicate organisation name). You can fix these later from the MSSP dashboard.
3
Customer M365 connection
Each customer needs to connect their Microsoft 365 environment. There are two ways to do this:Option A — Customer self-serviceShare the invite link from the Review step. The customer visits the link, creates their account, and follows the standard M365 connection flow (see Getting Started — Quick start).Option B — MSSP connects on behalf of the customerIf you have Global Admin credentials for the customer’s M365 tenant:
- From the MSSP dashboard, click Manage on the customer row
- Use the Impersonate button to enter the customer’s RAIDEN environment
- Navigate to the Microsoft 365 Connection page and follow the connection steps
Impersonation sessions last 4 hours and are rate-limited to 60 per hour. All impersonation activity is logged to the audit trail.
4
Manage your portfolio
Your MSSP dashboard at
yourslug.raidenhq.com/mssp provides:5
What happens after connection
Once a customer’s M365 is connected, RAIDEN works automatically:
- Audit log polling — Continuous, per customer tenant. Identity events (sign-ins, MFA, OAuth consent) are polled on a faster cadence — roughly every 2 minutes — so attacks like adversary-in-the-middle and token theft surface quickly. Other event types poll on cadences tuned to their volume and risk
- Baseline learning — 7–14 days to build user behavioural profiles
- Detection engine — 269 detection and signal rules covering device code phishing, token theft, OAuth abuse, Teams impersonation, impossible travel, mailbox manipulation, and more
- Findings & cases — Threats are surfaced as findings and grouped into cases. These are visible both in the customer’s environment and in your MSSP dashboard summary
Customer capacity
New MSSP accounts start on the trial plan, which has no customer-tenant limit — you can add and connect as many customers as you need to evaluate RAIDEN across your full portfolio. Higher plan tiers also carry their own capacity, and enterprise plans are uncapped. If you ever see an unexpected “customer limit reached” message, your account plan is unrecognised and has fallen back to a small default. Contact [email protected] and we will correct the plan on your account.Next steps
- Send invite links — Ensure every customer connects their M365 tenant so detections can begin
- Review early findings — After the first few poll cycles, check for initial detections and tune (mark false positives, add VPN exclusions, etc.)
- Invite SOC team members — Add analysts to your MSSP account from Settings
- Monitor the portfolio dashboard — Check the health summary regularly for new critical findings across your customer base
Cross-tenant intel propagation on true-positive closure
When an MSSP partner closes a case as a True Positive in one customer’s environment, RAIDEN automatically propagates the relevant threat intelligence to all other tenants in the same MSSP fleet. Specifically:- The attacker’s IP addresses, ASNs, and infrastructure indicators from the closed case are added to the fleet’s shared threat intel feed
- Other tenant environments immediately benefit from these indicators — new sign-ins matching the same infrastructure will generate findings in those tenants without any manual configuration
Getting help
Email [email protected] for support. Standard queries receive a response within 1 business day. For active compromise situations, include URGENT in the subject line. When raising a support request, include:- Your organisation name or MSSP slug (shown in Settings → Account)
- The Case or Alert ID if asking about a specific detection
- A brief description of what you expected to see and what you saw instead