Microsoft Sentinel
Cloud and workloads

Enable Entity Behavior Analytics

In brief

The article now links to required roles and permissions, lists Amazon GuardDuty and supported CommonSecurityLog vendor events, and adds guidance for UEBA tables, schemas, and related articles.

What Defender admins need to know

Administrators have clearer references for validating access, supported data sources, and UEBA investigation data.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can enable UEBA and configure data sources directly from the UEBA tab. See Access UEBA from the UEBA tab.

This article explains how to enable UEBA and configure data sources from your Microsoft Sentinel workspace settings and from supported data connectors. Before you begin, review the Prerequisites section for required roles and permissions.

For more information about UEBA, see Identify threats with entity behavior analytics.

- AAD Managed Identity Signin logs (Microsoft Entra ID)
- AAD Service Principal Signin logs (Microsoft Entra ID)
- AWS CloudTrail
- Amazon GuardDuty
- `CommonSecurityLog` for supported Check Point, Fortinet, and Zscaler events
- Device Logon Events
- Okta CL
- GCP Audit Logs

UEBA analyzes identity signals and supported network and cloud signals. For more information about UEBA data sourcesthe authoritative list of sources, required tables, supported vendor logs, and anomalies,field requirements, see [Microsoft Sentinel UEBA reference](./ueba-reference.md) and. For anomaly details, see [UEBA anomalies](./anomalies-reference.md#ueba-anomalies).
1. From the Microsoft Defender portal navigation menu, select **Settings** > **Microsoft Sentinel** > **SIEM workspaces**.
1. Select the workspace you want to configure.
1. From the workspace configuration page, select **Anomalies** and toggle on **Detect Anomalies**.

UEBA investigation and hunting data is available in tables such as `BehaviorAnalytics` and `BehaviorInfo`. For table schemas and usage guidance, see [Microsoft Sentinel UEBA reference](ueba-reference.md) and [Translate raw security logs to behavioral insights using UEBA behaviors](entity-behaviors-layer.md).

Install the UEBA Essentials solution (optional)

Enable the UEBA behaviors layer

The UEBA behaviors layer generates enriched summaries of activity observed in multiple data sources. Unlike alerts or anomalies, behaviors don't necessarily indicate risk. They create an abstraction layer that optimizes your data for investigations, hunting, and detection by improving clarity, context, and correlation. Behavior records can also include anomaly insights and contextual enrichment associated with the activity.

For more information about the UEBA behaviors layer and how to enable it, see Enable the UEBA behaviors layer in Microsoft Sentinel.

Next stepsRelated articles