Microsoft Defender XDR
General

DataSecurityBehaviors

In brief

The table documentation removes the Preview label and prerelease notice and adds the `PolicyInfo` and `Policies` columns.

What Defender admins need to know

Administrators can reference these documented policy-related fields when querying the table; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

DataSecurityBehaviors (Preview)

[!INCLUDE Microsoft Defender XDR rebranding]

The DataSecurityBehaviors table in the advanced hunting

The DataSecurityBehaviors table in the advanced hunting schema contains insights about potentially suspicious user behaviors that violate the user-defined or default policies configured in the Microsoft Purview suite of solutions.

Insights cover a range of data security related behaviors like behaviors involving exfiltration, obfuscation, risky interactions with AI applications, and others. Insights are generated by aggregating user behaviors over a calendar day and comparing them with previous activity, peer group activity, or other activities done by the user. Insights also capture summaries of various risk pivots like sensitive data, risky destinations, and the like. |AccountUpn| string| User principal name (UPN) of the account| |AccountEmail| string| Email address of the account| |Application| string |Application that performed the recorded action| |PolicyInfo|dynamic|Policy information associated with the behavior| |Policies|string|List of insider risk management policies associated with the behavior| |DeviceInfo| dynamic| List of device information for the device involved in this behavior, including device ID, device name, and the number of events in which the device is involved; in JSON array format| |SensitivityLabelInfo| dynamic| List of sensitivity labels assigned to content involved in this behavior, including the unique identifier for the Microsoft Information Protection sensitivity label assigned to the related content, the name of the sensitivity label, and the number of events in the behavior involving this label; in JSON array format| |SensitiveInfoTypesInfo| dynamic |List of sensitive info types detected in the content involved in this behavior, including the unique identifier for the sensitive info type, the name of the sensitive info type, and the number of events in the behavior involving this sensitive info type; in JSON array format|