Microsoft Sentinel
Developer and API

Configure Connector Login Detection

In brief

The documentation now highlights that the machine learning algorithm needs 30 days of Windows Security events to establish a user-behavior baseline before detecting incidents.

What Defender admins need to know

Plan for at least 30 days of collected Windows Security events before expecting detections.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to enable the detection of anomalous RDP logins, so that analysts can identify and respond to the resulting potential security threats in my network.

  1. You must be collecting RDP login data (Event ID 4624) through the Security events or Windows Security Events data connectors. Make sure you have selected a Windows security event set besides "None", or created a data collection rule that includes this event ID, to stream into Microsoft Sentinel.

  2. From the Microsoft Sentinel portal, select Analytics, and then select the Rule templates tab. Choose the (Preview) Anomalous RDP Login Detection rule, and move the Status slider to Enabled.

As the machine learning algorithm requires 30 days' worth of data to build a baseline profile of user behavior, you must allow 30 days of Windows Security events data to be collected before any incidents can be detected.

Next steps

  1. From the Microsoft Sentinel portal, select Analytics, and then select the Rule templates tab. Choose the (Preview) Anomalous RDP Login Detection rule, and move the Status slider to Enabled.

Next steps