Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

Koonnamchok Klongkaew 140 Reputation points
2024-06-20T09:25:17.94+00:00

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

'Investigation priority score' feature and 'Investigation priority score increase policy' will be phased out in the coming weeks, This will impact all existing related policies, as they will be removed.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
{count} votes

1 answer

Sort by: Most helpful
  1. SamiL 0 Reputation points MVP
    2024-07-08T05:11:59.5966667+00:00

    Hi @Koonnamchok Klongkaew

    To the best of my knowledge the change you're referring to is only affecting to the Investigation priority score alert in Defender for Cloud Apps. You can still use MDA UEBA as before and investigation score remains in the product after the change.

    MS Learn states the following:

    We're gradually retiring the Investigation priority score increase alert from Microsoft Defender for Cloud Apps by August 2024. The investigation priority score and the procedure described in this article are not affected by this change.

    MDA-3

    Details - https://learn.microsoft.com/en-us/defender-cloud-apps/investigate-anomaly-alerts#deprecation-timeline

    If you want to leverage the investigation priority score alerts in the future I suggest you to use the hunting query mentioned on the article (instead of policy template) and adjust that one based on your needs.

    0 comments No comments