Agent Foskett Academy • Microsoft Sentinel • Module 2 • Lesson 16

Lesson 16 — Microsoft Sentinel Investigation Graph

Microsoft Sentinel incidents can contain multiple alerts, accounts, devices, IP addresses, URLs and other connected entities.

The Investigation Graph helps analysts visualise those relationships, expand related activity and identify where the investigation should go next.

It turns complex incident evidence into a connected view while keeping the underlying telemetry available for validation.

Incidents show what was detected. The Investigation Graph shows how the evidence is connected.
Agent Foskett Microsoft Sentinel Investigation Graph lesson
What you will learn

This lesson explains how analysts use the Investigation Graph to understand relationships inside Microsoft Sentinel incidents.

What the Investigation Graph is
Nodes, alerts and entities
Expanding related activity
Safe investigation pivots

Learning objectives

After completing this lesson, you should understand how the Microsoft Sentinel Investigation Graph helps analysts explore relationships inside an incident.

  • Explain what the Investigation Graph is.
  • Recognise nodes, alerts, entities and relationships.
  • Understand how analysts expand related activity.
  • Use entity pivots to continue an investigation.
  • Validate graph connections against underlying telemetry.

The problem this solves

Complex incidents may contain many alerts, users, devices, IP addresses and other entities.

The Investigation Graph helps analysts understand how those objects are connected without manually reconstructing every relationship.

What is the Investigation Graph?

The Microsoft Sentinel Investigation Graph is a visual investigation experience that displays incidents, alerts and mapped entities as connected nodes.

It helps analysts explore relationships between accounts, hosts, IP addresses, URLs, files and other security objects.

Agent Foskett tip:

The graph helps you see relationships. It does not prove that every connected entity is malicious.

How the graph fits into an investigation

Incident │ ├── Alert │ ├── Account │ ├── Device │ └── IP Address │ ├── Related Alert │ ├── URL │ └── File │ ▼ Expand entities and review relationships │ ▼ Validate evidence and build the investigation timeline

Nodes

Each object shown in the graph is represented as a node.

Nodes may represent an incident, alert, account, host, IP address, URL, file, mailbox or another mapped entity.

Relationships

Lines between nodes show that Sentinel has identified a relationship between those objects.

The relationship may come from an alert, analytics rule, entity mapping or connected investigation data.

Expanding the graph

Analysts can select an entity and expand related activity to reveal additional alerts, events or connected entities.

This is useful when a suspicious account or device appears across multiple parts of the incident.

Entity pivots

The Investigation Graph allows analysts to pivot from one entity into broader context.

For example, an analyst may move from a user account to related sign-ins, devices, IP addresses and alerts.

Alerts and incidents

Alerts provide the detection evidence. The incident groups related alerts into a case.

The graph helps analysts understand how the incident's alerts and entities overlap.

Investigation timeline

The graph should be used alongside the incident timeline and underlying logs.

Visual relationships become more valuable when analysts also confirm when each event occurred.

Real-world account compromise example

Graph nodeInvestigation value
User accountIdentifies the potentially compromised identity.
Suspicious IP addressShows where the sign-in or remote activity originated.
Managed deviceHelps determine whether the activity came from a known endpoint.
Mailbox alertShows whether inbox rules, forwarding or unusual email activity occurred.
Related alertsReveals whether the same account appears across multiple detections.

Using Bookmarks

Bookmarks can preserve important events found while exploring graph relationships.

This allows the analyst to retain evidence and notes while continuing the wider investigation.

Using entity pages

Entity pages provide deeper context for accounts, hosts, IP addresses and other investigation objects.

Use them to review activity history, related alerts and additional behavioural information.

Common mistake

A common mistake is treating every graph connection as proof of malicious activity.

Some relationships are expected business activity and must be validated against the underlying evidence.

What to validate

  • The source alert and analytics rule
  • Entity identifiers and timestamps
  • The underlying KQL results
  • Expected user and device behaviour
  • Whether the relationship is causal or only correlated

Agent Foskett investigation tip

Use the graph to find the next question.

The Investigation Graph is most useful when it reveals where to pivot next. Always return to the logs to validate what the visual relationship actually means.

Best practices

  • Start with the incident's strongest evidence.
  • Expand one entity at a time.
  • Track timestamps while following relationships.
  • Save important findings as Bookmarks.
  • Confirm connections using raw telemetry.

Agent Foskett takeaway

The Investigation Graph turns connected incident evidence into a visual map.

It helps analysts understand relationships quickly, but final conclusions must still come from validated telemetry.

Lesson summary
The Microsoft Sentinel Investigation Graph visualises relationships between incidents, alerts and entities. Analysts use it to expand activity, pivot between accounts, devices and IP addresses, and identify the next investigation step while validating every connection against the underlying logs.
Sentinel Academy Home

Microsoft Sentinel Investigation Graph

The Microsoft Sentinel Investigation Graph helps SOC analysts visualise relationships between incidents, alerts, accounts, hosts, IP addresses, URLs, files and other mapped entities.

Microsoft Sentinel Lesson 16

This Agent Foskett Microsoft Sentinel Academy lesson explains Investigation Graph nodes, entity relationships, investigation pivots, timelines, Bookmarks and evidence validation.