Lesson 16 — Microsoft Sentinel Investigation Graph
Microsoft Sentinel incidents can contain multiple alerts, accounts, devices, IP addresses, URLs and other connected entities.
The Investigation Graph helps analysts visualise those relationships, expand related activity and identify where the investigation should go next.
It turns complex incident evidence into a connected view while keeping the underlying telemetry available for validation.
What you will learn
This lesson explains how analysts use the Investigation Graph to understand relationships inside Microsoft Sentinel incidents.
Learning objectives
After completing this lesson, you should understand how the Microsoft Sentinel Investigation Graph helps analysts explore relationships inside an incident.
- Explain what the Investigation Graph is.
- Recognise nodes, alerts, entities and relationships.
- Understand how analysts expand related activity.
- Use entity pivots to continue an investigation.
- Validate graph connections against underlying telemetry.
The problem this solves
Complex incidents may contain many alerts, users, devices, IP addresses and other entities.
The Investigation Graph helps analysts understand how those objects are connected without manually reconstructing every relationship.
What is the Investigation Graph?
The Microsoft Sentinel Investigation Graph is a visual investigation experience that displays incidents, alerts and mapped entities as connected nodes.
It helps analysts explore relationships between accounts, hosts, IP addresses, URLs, files and other security objects.
The graph helps you see relationships. It does not prove that every connected entity is malicious.
How the graph fits into an investigation
Nodes
Each object shown in the graph is represented as a node.
Nodes may represent an incident, alert, account, host, IP address, URL, file, mailbox or another mapped entity.
Relationships
Lines between nodes show that Sentinel has identified a relationship between those objects.
The relationship may come from an alert, analytics rule, entity mapping or connected investigation data.
Expanding the graph
Analysts can select an entity and expand related activity to reveal additional alerts, events or connected entities.
This is useful when a suspicious account or device appears across multiple parts of the incident.
Entity pivots
The Investigation Graph allows analysts to pivot from one entity into broader context.
For example, an analyst may move from a user account to related sign-ins, devices, IP addresses and alerts.
Alerts and incidents
Alerts provide the detection evidence. The incident groups related alerts into a case.
The graph helps analysts understand how the incident's alerts and entities overlap.
Investigation timeline
The graph should be used alongside the incident timeline and underlying logs.
Visual relationships become more valuable when analysts also confirm when each event occurred.
Real-world account compromise example
| Graph node | Investigation value |
|---|---|
| User account | Identifies the potentially compromised identity. |
| Suspicious IP address | Shows where the sign-in or remote activity originated. |
| Managed device | Helps determine whether the activity came from a known endpoint. |
| Mailbox alert | Shows whether inbox rules, forwarding or unusual email activity occurred. |
| Related alerts | Reveals whether the same account appears across multiple detections. |
Using Bookmarks
Bookmarks can preserve important events found while exploring graph relationships.
This allows the analyst to retain evidence and notes while continuing the wider investigation.
Using entity pages
Entity pages provide deeper context for accounts, hosts, IP addresses and other investigation objects.
Use them to review activity history, related alerts and additional behavioural information.
Common mistake
A common mistake is treating every graph connection as proof of malicious activity.
Some relationships are expected business activity and must be validated against the underlying evidence.
What to validate
- The source alert and analytics rule
- Entity identifiers and timestamps
- The underlying KQL results
- Expected user and device behaviour
- Whether the relationship is causal or only correlated
Agent Foskett investigation tip
The Investigation Graph is most useful when it reveals where to pivot next. Always return to the logs to validate what the visual relationship actually means.
Best practices
- Start with the incident's strongest evidence.
- Expand one entity at a time.
- Track timestamps while following relationships.
- Save important findings as Bookmarks.
- Confirm connections using raw telemetry.
Agent Foskett takeaway
The Investigation Graph turns connected incident evidence into a visual map.
It helps analysts understand relationships quickly, but final conclusions must still come from validated telemetry.
Related Agent Foskett learning
Continue learning
Microsoft Sentinel Investigation Graph
The Microsoft Sentinel Investigation Graph helps SOC analysts visualise relationships between incidents, alerts, accounts, hosts, IP addresses, URLs, files and other mapped entities.
Microsoft Sentinel Lesson 16
This Agent Foskett Microsoft Sentinel Academy lesson explains Investigation Graph nodes, entity relationships, investigation pivots, timelines, Bookmarks and evidence validation.
