Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

Koonnamchok Klongkaew 140 Reputation points
2024-06-20T09:25:17.94+00:00

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

'Investigation priority score' feature and 'Investigation priority score increase policy' will be phased out in the coming weeks, This will impact all existing related policies, as they will be removed.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. SamiL 0 Reputation points MVP
    2024-07-08T05:11:59.5966667+00:00

    Hi @Koonnamchok Klongkaew

    To the best of my knowledge the change you're referring to is only affecting to the Investigation priority score alert in Defender for Cloud Apps. You can still use MDA UEBA as before and investigation score remains in the product after the change.

    MS Learn states the following:

    We're gradually retiring the Investigation priority score increase alert from Microsoft Defender for Cloud Apps by August 2024. The investigation priority score and the procedure described in this article are not affected by this change.

    MDA-3

    Details - https://learn.microsoft.com/en-us/defender-cloud-apps/investigate-anomaly-alerts#deprecation-timeline

    If you want to leverage the investigation priority score alerts in the future I suggest you to use the hunting query mentioned on the article (instead of policy template) and adjust that one based on your needs.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.