Email/Phone Indicators in Account Entity Types

Venkat Rambatla 1 Reputation point
2020-08-18T13:23:07.837+00:00

Hi There,

As Sentinel supports only four entity types -

  1. Account 2. IP 3. Host 4. URL

Can we use Email or Phone Number in the logs and map it to Account Entity Type?

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Saurabh Sharma 23,851 Reputation points Microsoft Employee Moderator
    2020-08-20T14:31:27.197+00:00

    @Venkat Rambatla I have received confirmation on your ask and here is correction to my previous comment -
    You can indeed use the account to hold the email since it is a valid account name - however, not zip code and phone number.
    The product team is also aware of limitation of not showing all columns under different entity types (Account, IP, Host and URL) and currently working on an improvement that would allow using a wide range of entity types.

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    2 people found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.