Working with Automation in Sentinel UEBA and Identity Protection

Andre P 20 Reputation points
2023-03-02T00:03:22.1766667+00:00

I was looking into the architecture of how UEBA Engine works and how it generates its Behavior Analytics. I wanted to look into some automation. Being that if I force flag users as high risk to trip password resets and such through Identity Protection, could this effect UEBA?

Entity behavior analytics architecture

Microsoft Security Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. David Broggy 6,291 Reputation points MVP Volunteer Moderator
    2023-03-02T02:16:01.59+00:00

    Hi Andre,

    UEBA is mostly calculated from a baseline of user activity so I'm not aware of a way to 'rig' the outcome using forced values.

    Javier is a great presenter on this topic:
    https://www.youtube.com/watch?v=dLVAkSLKLyQ&ab_channel=MicrosoftSecurityCommunity

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.