Agent Foskett Academy • Microsoft Sentinel • Module 2 • Lesson 17

Lesson 17 — Microsoft Sentinel UEBA

Traditional detections look for known patterns, thresholds and Indicators of Compromise.

User and Entity Behavior Analytics takes a different approach by learning how users, hosts, IP addresses and applications normally behave, then highlighting activity that departs from those baselines.

UEBA gives analysts additional context for prioritising suspicious behaviour, investigating compromised accounts and identifying unusual activity that may not match a traditional rule.

Rules detect known patterns. UEBA highlights behaviour that is unusual for the entity.
Agent Foskett Microsoft Sentinel UEBA lesson
What you will learn

This lesson explains how Microsoft Sentinel UEBA builds behavioural context and supports anomaly-focused investigations.

What UEBA is
Behavioural baselines
Anomalies and entity insights
Safe investigation practices

Learning objectives

After completing this lesson, you should understand how Microsoft Sentinel User and Entity Behavior Analytics supports advanced threat detection and investigation.

  • Explain what UEBA is.
  • Understand behavioural baselines and peer comparisons.
  • Recognise entities, anomalies and behavioural insights.
  • Use UEBA context during incident investigations.
  • Understand the limitations of anomaly-based evidence.

The problem this solves

Attackers often use valid accounts, normal tools and legitimate services.

UEBA helps analysts identify when otherwise valid activity behaves differently from the entity's established patterns.

What is Microsoft Sentinel UEBA?

User and Entity Behavior Analytics analyses logs and alerts from connected data sources to create behavioural profiles for entities such as users, hosts, IP addresses and applications.

Machine learning then compares current activity against established baselines and highlights anomalies that may deserve investigation.

Agent Foskett tip:

An anomaly is an investigation lead, not proof of compromise. Always validate the behaviour against the surrounding telemetry.

How UEBA works

Connected security data │ ▼ Entity activity collected │ ├── User behaviour ├── Host behaviour ├── IP activity └── Application activity │ ▼ Dynamic behavioural baseline │ ├── Entity history ├── Peer behaviour └── Organisation-wide patterns │ ▼ Anomalous activity identified │ ▼ Entity insights and investigation context

Behavioural baselines

A baseline represents what is normally expected for an entity.

Examples include usual sign-in locations, devices, resources, working hours, applications and activity patterns.

Dynamic learning

UEBA baselines are not static allow lists.

They change as Microsoft Sentinel observes new activity and learns how the entity and its peers normally behave.

Entity history

UEBA considers the entity's own historical activity.

A sign-in from a country never previously used by the account may therefore receive more attention than a familiar location.

Peer comparison

Sentinel can compare an entity with similar users or systems.

Activity may be unusual even when it is technically permitted, especially if the entity behaves differently from its peer group.

Organisation-wide context

UEBA can also compare behaviour with wider organisational patterns.

This helps identify rare resources, locations, applications or action types across the environment.

Common entity types

  • User accounts
  • Hosts and devices
  • IP addresses
  • Applications
  • Cloud resources
  • Other mapped investigation entities

Examples of behavioural anomalies

Observed behaviourWhy it may matter
Sign-in from an unusual geographic locationThe account is operating outside its normal location profile.
Access to a resource rarely used by the entityThe user or application may be exploring unfamiliar systems.
Activity from a new device or ISPThe session may not match the entity's historical behaviour.
Unusual volume of operationsThe entity may be performing automated, abusive or compromised activity.
Behaviour uncommon among peersThe activity differs from users or systems with similar roles.

Entity pages

Entity pages bring together facts, timelines, related alerts and behavioural insights for a selected entity.

They help analysts understand whether suspicious activity is isolated or part of a longer pattern.

UEBA and incidents

UEBA enrichments can provide additional context inside alerts and incidents.

This context helps analysts prioritise entities whose behaviour appears risky or unusual.

UEBA and the Investigation Graph

UEBA adds behavioural context to the entities analysts explore through incident investigations.

The graph shows how entities connect, while UEBA helps explain whether their behaviour is unusual.

UEBA and Hunting

Hunters can use behavioural anomalies to form new hypotheses and identify accounts or systems that deserve deeper review.

Successful hunts may later become analytics rules or repeatable investigation procedures.

Real-world compromised account example

Valid user credentials used │ ▼ Sign-in succeeds │ ├── New country ├── New device ├── Unusual ISP └── Rare cloud resource accessed │ ▼ UEBA identifies anomalous behaviour │ ▼ Analyst reviews entity timeline, alerts and raw sign-in evidence │ ▼ Account compromise confirmed or dismissed

Enabling UEBA

UEBA is enabled from the Microsoft Sentinel entity behaviour settings or while configuring supported data connectors.

Only connected and supported data sources can contribute the behavioural telemetry required by the service.

Data quality matters

Behavioural analytics depends on the quality and breadth of the connected data.

Missing identity, device or activity telemetry can reduce the context available to the analyst.

Common mistake

A common mistake is escalating every unusual event as malicious.

Travel, role changes, new projects and administrative work can all create legitimate anomalies.

What to validate

  • The entity's historical activity
  • Peer and organisational behaviour
  • Sign-in and device evidence
  • Related incidents and alerts
  • Business context and approved changes

Agent Foskett investigation tip

Unusual is not the same as malicious.

Use UEBA to prioritise the investigation, then confirm the event with timestamps, entity history, related alerts and the underlying logs.

Best practices

  • Connect high-value identity and activity sources.
  • Review entity history before escalating.
  • Combine UEBA with incident and threat intelligence context.
  • Document legitimate business explanations.
  • Use anomalies to guide hunting, not replace analysis.

Agent Foskett takeaway

UEBA helps Microsoft Sentinel understand what normal behaviour looks like for users and other entities.

It gives analysts a powerful way to prioritise unusual activity, but every anomaly must still be validated against the evidence.

Lesson summary
Microsoft Sentinel UEBA builds dynamic behavioural profiles for users and other entities, compares current activity with historical, peer and organisational baselines, and highlights anomalies that may require investigation. Analysts should use these insights to prioritise evidence, not as automatic proof of compromise.
Sentinel Academy Home

Microsoft Sentinel User and Entity Behavior Analytics

Microsoft Sentinel UEBA builds dynamic behavioural profiles for users, hosts, IP addresses, applications and other entities, then identifies anomalies using historical, peer and organisational context.

Microsoft Sentinel Lesson 17

This Agent Foskett Microsoft Sentinel Academy lesson explains UEBA baselines, machine learning, anomaly detection, entity pages, behavioural insights, investigations and SOC validation practices.