Microsoft Defender XDR
Identity protection

Investigate an identity

In brief

The page now documents connector-dependent remediation actions, including that Confirm safe resets both the identity risk score and Microsoft Entra risk level. It also expands the identity timeline to include sign-ins, audit events, risk signals, Conditional Access evaluations, correlated accounts, and additional data tables.

What Defender admins need to know

Administrators can use the broader timeline context and updated risk-reset guidance during identity investigations. No administrator action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate an identity

Identity actions

From the Overview page, use the Actions menu to trigger remediation actions.remediation actions on the identity. Actions apply to the accounts associated with the identity and depend on which connectors are enabled, spanning on-premises Active Directory, Microsoft Entra ID, identity and access management (IAM) systems, and SaaS apps. Available actions include:

  • Enable, disable,can include disabling or suspendenabling accounts, revoking sessions, forcing a password change, and marking the user in Microsoft Entra ID
  • Requireas compromised. You can also view the user to sign in again or force a password reset
  • View Microsoft Entraidentity's account settings, related governance,settings.

    For the user's owned files, or shared files

full list of remediation actions and the identity providers and connected apps that support them, see Remediation actions in Microsoft Defender for Identity.

:::image type="content" source="media/investigate-users/identity-actions.png" alt-text="Screenshot of the identity page with the identity actions menu showing." lightbox="media/investigate-users/identity-actions.png":::

The Observed in organization tab shows where and how the identity appears across the environment, helping analysts understand blast radius and potential lateral movement.

This tab can include:

| Section | Description |

Microsoft Defender uses internal correlation logic to determine the primary account.

:::image type="content" source="media/investigate-users/identity-observed-in-organization.png" alt-text="Screenshot of the Observed in organization tab on the Identity page in Microsoft Defender." lightbox="media/investigate-users/identity-observed-in-organization.png":::

This tab can include:

| Section | Description |

Microsoft Defender uses internal correlation logic to determine the primary account.

In the Accounts table, the primary account is identified by the primary account icon next to the account's display name.

Risk score tab

| Risk Trend | A line chart that shows how the risk score changed over a configurable time period (for example, 30 days). Select Go to timeline to view the full activity timeline. | | Likelihood of Compromise Details | A bar chart that shows alert distribution across MITRE ATT&CK categories, with a filterable alert table. Use the Active alerts only toggle to focus on unresolved alerts. Filter by account set, status, or kill chain stage. |

SelectThe Confirm safe action now includes Reset risk atfor both the top ofidentity risk score and the tab to manually reset the identity'sMicrosoft Entra risk score, for example after completing remediation.level. For more information, see Remediation actions in Microsoft Defender for Identity.

Timeline tab

The Timeline tab provides a chronological, identity-centric view of activity and alerts correlated to the identity across your environment: on-premises Active Directory, Microsoft Entra ID, IAM and other identity providers, SaaS applications, cloud, and endpoints. It aggregates data from integrated Microsoft security products, such as Microsoft Defender for Identity, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Sentinel.

The timeline brings together sign-ins, audit events, risk signals, applied controls, and Conditional Access evaluations alongside all workload activity, so you can reconstruct sequences of activity and correlate events during an investigation. Because activity is correlated at the identity level, the timeline includes events where the identity is the actor or the target. It covers every account linked to the identity, including manually and policy-based (custom) correlated accounts. Duplicate events are removed so the same activity isn't shown twice; for example, when a sign-in appears in both the Entra ID and cloud app data, the timeline favors the Entra ID source.

:::image type="content" source="media/investigate-users/identity-timeline.png" alt-text="Screenshot of the Timeline tab on the Identity page in Microsoft Defender." lightbox="media/investigate-users/identity-timeline.png":::

The following data types are available in the timeline:

  • A user's impacted alerts
  • Active Directory and Microsoft Entra ID activities, including Microsoft Entra sign-ins and Microsoft Graph activity (audit) events
  • Microsoft Entra ID risk signals and Conditional Access evaluation results, shown inline
  • Cloud apps events
  • Device logon events
  • Directory services changes
  • Activities associated with custom (manually or policy-based) correlated accounts

Tables aggregated into the timeline

The timeline draws from multiple advanced hunting tables and normalizes them into a single schema. The following tables are used to build the identity timeline:

  • AlertInfo
  • IdentityLogonEvents
  • IdentityQueryEvents
  • IdentityDirectoryEvents
  • CloudAppEvents
  • DeviceLogonEvents
  • EntraIdSignInEvents
  • GraphApiAuditEvents

Timeline schema

The timeline normalizes events from the different source tables into a unified schema. Some columns are shown by default; others can be added from Customize columns. The following columns are available:

Column Type Shown by default Filterable by default
Time DateTime Yes Yes
Type Enum (Event or Alert) Yes Yes
Title String Yes Yes
Source provider account ID String Yes Yes
Account display name String Yes Yes
Source provider String Yes Yes
IP address String Yes Yes
Device String Yes Yes
Risk/Severity String Yes Yes
Location String Yes Yes
Conditional Access policies Dynamic Yes No
Source table String Yes No
Sentinel workspace String No No
Target Dynamic No Not filterable
Session ID String No No
Unique token identifier String No No
Additional information Dynamic No Not filterable
ReportId String No No

Event details pane

Select an event in the timeline to open a side pane with the event details. The pane organizes the information into tabs. For Microsoft Entra ID sign-in events, the pane includes a Conditional Access tab that shows the Conditional Access policies evaluated during the sign-in, including each policy's name, grant controls, and result (for example, Success, Not applied, or Block). Reviewing these evaluation results helps analysts understand which controls applied during an investigation.

:::image type="content" source="media/investigate-users/identity-timeline-conditional-access.png" alt-text="Screenshot of the sign-in event details pane on the Identity timeline showing Conditional Access policy evaluation results." lightbox="media/investigate-users/identity-timeline-conditional-access.png":::

Security recommendations tab

techniques
  • Alert severity and status
  • Country/region where the client IP address is geolocated
  • Protocol used during the communication
  • Target device (optional, viewable by customizing columns)
  • Number of times the activity happened (optional, viewable by customizing columns)
  • Working with the timeline

    • Custom time range picker: Choose a timeframe to focus your investigation on the last 24 hours, the last 3 days, and so on. Or choose a specific timeframe by selecting Custom range. Filtered data older than 30 days is displayed in seven-day intervals.

    • Timeline filters: Use the timeline filters to narrow results by Type (alerts and/or user's related activities), Alert severity, Activity type, App, Location, or Protocol. Each filter depends on the others, and the options in each filter only contain data that's relevant for the specific user.

    • Customized columns: Select the Customize columns button to choose which columns to expose in the timeline.

    • Export: Export the timeline to a CSV file. Export is limited to the first 5,000 records and contains the data as displayed in the UI (same filters and columns).

    Security recommendations tab