Lesson 17 — Microsoft Sentinel UEBA
Traditional detections look for known patterns, thresholds and Indicators of Compromise.
User and Entity Behavior Analytics takes a different approach by learning how users, hosts, IP addresses and applications normally behave, then highlighting activity that departs from those baselines.
UEBA gives analysts additional context for prioritising suspicious behaviour, investigating compromised accounts and identifying unusual activity that may not match a traditional rule.
What you will learn
This lesson explains how Microsoft Sentinel UEBA builds behavioural context and supports anomaly-focused investigations.
Learning objectives
After completing this lesson, you should understand how Microsoft Sentinel User and Entity Behavior Analytics supports advanced threat detection and investigation.
- Explain what UEBA is.
- Understand behavioural baselines and peer comparisons.
- Recognise entities, anomalies and behavioural insights.
- Use UEBA context during incident investigations.
- Understand the limitations of anomaly-based evidence.
The problem this solves
Attackers often use valid accounts, normal tools and legitimate services.
UEBA helps analysts identify when otherwise valid activity behaves differently from the entity's established patterns.
What is Microsoft Sentinel UEBA?
User and Entity Behavior Analytics analyses logs and alerts from connected data sources to create behavioural profiles for entities such as users, hosts, IP addresses and applications.
Machine learning then compares current activity against established baselines and highlights anomalies that may deserve investigation.
An anomaly is an investigation lead, not proof of compromise. Always validate the behaviour against the surrounding telemetry.
How UEBA works
Behavioural baselines
A baseline represents what is normally expected for an entity.
Examples include usual sign-in locations, devices, resources, working hours, applications and activity patterns.
Dynamic learning
UEBA baselines are not static allow lists.
They change as Microsoft Sentinel observes new activity and learns how the entity and its peers normally behave.
Entity history
UEBA considers the entity's own historical activity.
A sign-in from a country never previously used by the account may therefore receive more attention than a familiar location.
Peer comparison
Sentinel can compare an entity with similar users or systems.
Activity may be unusual even when it is technically permitted, especially if the entity behaves differently from its peer group.
Organisation-wide context
UEBA can also compare behaviour with wider organisational patterns.
This helps identify rare resources, locations, applications or action types across the environment.
Common entity types
- User accounts
- Hosts and devices
- IP addresses
- Applications
- Cloud resources
- Other mapped investigation entities
Examples of behavioural anomalies
| Observed behaviour | Why it may matter |
|---|---|
| Sign-in from an unusual geographic location | The account is operating outside its normal location profile. |
| Access to a resource rarely used by the entity | The user or application may be exploring unfamiliar systems. |
| Activity from a new device or ISP | The session may not match the entity's historical behaviour. |
| Unusual volume of operations | The entity may be performing automated, abusive or compromised activity. |
| Behaviour uncommon among peers | The activity differs from users or systems with similar roles. |
Entity pages
Entity pages bring together facts, timelines, related alerts and behavioural insights for a selected entity.
They help analysts understand whether suspicious activity is isolated or part of a longer pattern.
UEBA and incidents
UEBA enrichments can provide additional context inside alerts and incidents.
This context helps analysts prioritise entities whose behaviour appears risky or unusual.
UEBA and the Investigation Graph
UEBA adds behavioural context to the entities analysts explore through incident investigations.
The graph shows how entities connect, while UEBA helps explain whether their behaviour is unusual.
UEBA and Hunting
Hunters can use behavioural anomalies to form new hypotheses and identify accounts or systems that deserve deeper review.
Successful hunts may later become analytics rules or repeatable investigation procedures.
Real-world compromised account example
Enabling UEBA
UEBA is enabled from the Microsoft Sentinel entity behaviour settings or while configuring supported data connectors.
Only connected and supported data sources can contribute the behavioural telemetry required by the service.
Data quality matters
Behavioural analytics depends on the quality and breadth of the connected data.
Missing identity, device or activity telemetry can reduce the context available to the analyst.
Common mistake
A common mistake is escalating every unusual event as malicious.
Travel, role changes, new projects and administrative work can all create legitimate anomalies.
What to validate
- The entity's historical activity
- Peer and organisational behaviour
- Sign-in and device evidence
- Related incidents and alerts
- Business context and approved changes
Agent Foskett investigation tip
Use UEBA to prioritise the investigation, then confirm the event with timestamps, entity history, related alerts and the underlying logs.
Best practices
- Connect high-value identity and activity sources.
- Review entity history before escalating.
- Combine UEBA with incident and threat intelligence context.
- Document legitimate business explanations.
- Use anomalies to guide hunting, not replace analysis.
Agent Foskett takeaway
UEBA helps Microsoft Sentinel understand what normal behaviour looks like for users and other entities.
It gives analysts a powerful way to prioritise unusual activity, but every anomaly must still be validated against the evidence.
Related Agent Foskett learning
Continue learning
Microsoft Sentinel User and Entity Behavior Analytics
Microsoft Sentinel UEBA builds dynamic behavioural profiles for users, hosts, IP addresses, applications and other entities, then identifies anomalies using historical, peer and organisational context.
Microsoft Sentinel Lesson 17
This Agent Foskett Microsoft Sentinel Academy lesson explains UEBA baselines, machine learning, anomaly detection, entity pages, behavioural insights, investigations and SOC validation practices.
