| |

UEBA in Microsoft Sentinel: How to Use User and Entity Behaviour Analytics Effectively

UEBA in Microsoft Sentinel: Detect Insider Threats & Compromised Accounts

📅 May 2026⏱ 12 min read 🏷 Microsoft Sentinel · UEBA · Insider Threat

Traditional rule-based detection catches known attack patterns — but compromised accounts and malicious insiders often operate within legitimate activity thresholds, evading signature-based detection entirely. User and Entity Behaviour Analytics (UEBA) takes a fundamentally different approach: it builds a statistical baseline of normal behaviour for every user and entity, then scores deviations from that baseline as risk signals.

Microsoft Sentinel’s built-in UEBA capability enriches every investigation with entity context, peer group comparisons, and anomaly scoring — without requiring a separate product or data pipeline.

1. What Is UEBA?

UEBA analyses behaviour patterns across multiple dimensions for users, devices, applications, and IPs:

  • Temporal patterns — when does this user typically log in? What hours are normal?
  • Geolocation patterns — which countries and cities are expected for this user?
  • Peer group comparison — how does this user’s behaviour compare to colleagues in the same department or job role?
  • Resource access patterns — what resources does this user normally access? What would be anomalous?
  • Volume patterns — is the amount of data accessed or transferred within normal range?

When a user’s behaviour deviates significantly from their own baseline and from their peer group, UEBA surfaces this as an elevated risk score — giving analysts a prioritised signal to investigate.

2. How Sentinel UEBA Works

Sentinel UEBA ingests data from multiple sources simultaneously — Azure AD / Entra ID sign-in logs, Audit logs, Defender for Endpoint device events, and Microsoft 365 activity — and builds entity profiles over a learning period of 14–21 days. After the learning period, UEBA starts producing anomaly scores and insights.

Learning Period

14–21 days

Risk Score Range

0 – 10

Entity Types

User, Device, IP, App

Lookback Window

Rolling 30 days

UEBA data flows into three key tables: BehaviorAnalytics (anomalies and risk scores), IdentityInfo (entity enrichment data), and UserAccessAnalytics (resource access patterns). These tables are free to query once UEBA is enabled — they do not incur additional ingestion charges beyond what you already pay for the source data.

3. Enabling UEBA

UEBA is enabled at the workspace level in Sentinel settings. Once activated, you configure which data sources to feed into the UEBA engine:

  1. Navigate to Microsoft Sentinel → Settings → Entity behaviour
  2. Toggle UEBA on for your workspace
  3. Select data sources: Azure Active Directory (sign-in + audit logs), Microsoft 365, Defender for Endpoint
  4. Allow 14–21 days for the initial learning period to complete
  5. Enable the UEBA anomalies in your Sentinel Analytics rules to surface UEBA insights as incidents
⚠️ Prerequisites UEBA requires the following connectors to be active: Azure Active Directory (for SigninLogs and AuditLogs), and at least one endpoint data source. Without these, UEBA scores will be incomplete and may miss critical signals.

4. Key UEBA Tables

BehaviorAnalytics

The primary UEBA output table. Each row represents an anomalous activity detected for a user or entity, with a risk score and a human-readable insight explaining why the behaviour is anomalous.

FieldDescription
UserPrincipalNameThe user whose behaviour was analysed
RiskScoreScore 0–10; higher = more anomalous
InvestigationPriorityWeighted priority considering multiple signals
ActivityTypeLogOn, ResourceAccess, FileOperation, etc.
ActivityInsightsArray of insight strings explaining why this is anomalous
DevicesInsightsDevice-related anomaly context
IPCustomEntityThe IP address associated with the activity

IdentityInfo

Provides enrichment data for each identity — job title, department, manager, group memberships, risk level. Updated approximately every 24 hours from Azure AD.

5. UEBA Hunting Queries

Top High-Risk Users

BehaviorAnalytics
| where TimeGenerated > ago(7d)
| where RiskScore > 7
| summarize
    MaxRisk     = max(RiskScore),
    AvgRisk     = round(avg(RiskScore), 2),
    AnomalyCount = count()
  by UserPrincipalName
| order by MaxRisk desc
| take 20

Anomalies with Peer Group Context

BehaviorAnalytics
| where TimeGenerated > ago(14d)
| where ActivityInsights has "UncommonForPeer"
    or ActivityInsights has "FirstTimeForUser"
| extend Insights = parse_json(ActivityInsights)
| project
    TimeGenerated,
    UserPrincipalName,
    ActivityType,
    RiskScore,
    IPCustomEntity,
    Insights
| order by RiskScore desc

Impossible Travel via UEBA

BehaviorAnalytics
| where TimeGenerated > ago(7d)
| where ActivityInsights has "ImpossibleTravel"
| project
    TimeGenerated,
    UserPrincipalName,
    ActivityType,
    IPCustomEntity,
    ActivityInsights,
    InvestigationPriority
| order by InvestigationPriority desc

First-Time Access to Sensitive Resource

BehaviorAnalytics
| where TimeGenerated > ago(30d)
| where ActivityInsights has "FirstTimeForUser"
| where ActivityType == "ResourceAccess"
| summarize
    FirstAccess = min(TimeGenerated),
    AccessCount = count()
  by UserPrincipalName, IPCustomEntity
| order by FirstAccess desc

UEBA + Incident Correlation

// Find active incidents involving high-risk UEBA users
let HighRiskUsers =
    BehaviorAnalytics
    | where TimeGenerated > ago(7d)
    | where RiskScore > 6
    | summarize MaxRisk = max(RiskScore) by UserPrincipalName;
SecurityIncident
| where TimeGenerated > ago(7d)
| where Status != "Closed"
| mv-expand RelatedEntities = parse_json(RelatedEntities)
| extend UPN = tostring(RelatedEntities.Account.AadUserId)
| join kind=inner (HighRiskUsers) on $left.UPN == $right.UserPrincipalName
| project IncidentName, Title, Severity, Status, MaxRisk, UserPrincipalName

Enrich Alerts with IdentityInfo

SecurityAlert
| where TimeGenerated > ago(24h)
| where AlertSeverity in ("High", "Medium")
| extend Entities_parsed = parse_json(Entities)
| mv-expand Entities_parsed
| extend UPN = tostring(Entities_parsed.AadUserId)
| where isnotempty(UPN)
| join kind=leftouter (
    IdentityInfo
    | where TimeGenerated > ago(1d)
    | project AccountUPN, Department, JobTitle, RiskLevel, Manager
) on $left.UPN == $right.AccountUPN
| project TimeGenerated, AlertName, AlertSeverity, UPN, Department, JobTitle, RiskLevel

6. Entity Pages & Investigation

When you click on a user entity in a Sentinel incident, the Entity Page aggregates all UEBA data for that user into a single investigation view:

  • Risk score timeline — how has the user’s risk changed over the past 30 days?
  • Activity insights — all anomaly cards with explanations
  • Incident history — all past incidents involving this user
  • Peer group comparison — how does this user compare to colleagues?
  • Alert timeline — chronological view of all alerts

Entity pages eliminate the need to manually correlate data across multiple queries during an investigation. Start every user investigation on the entity page before diving into raw log queries.

7. Best Practices

  • Do not act on UEBA scores alone — use them as a prioritisation signal, not a verdict
  • Correlate UEBA anomalies with other signals: threat intel, EDR alerts, DLP events
  • Review the ActivityInsights field in detail — it explains why the behaviour is anomalous
  • Set up an analytic rule that fires when InvestigationPriority > 8 to create high-priority incidents automatically
  • After the 21-day learning period, run the top-risk-users query weekly as a standing hunt
// Analytic rule seed: auto-create incident for very high risk scores
BehaviorAnalytics
| where TimeGenerated > ago(1h)
| where InvestigationPriority >= 8
| summarize
    MaxPriority  = max(InvestigationPriority),
    MaxRisk      = max(RiskScore),
    AnomalyCount = count()
  by UserPrincipalName
| where MaxPriority >= 8
✅ UEBA Quick Start Enable UEBA today → connect Azure AD + MDE → wait 21 days → run the top-risk-users query → incorporate UEBA risk scores into your weekly threat hunt review. The ROI on insider threat and compromised account detection typically becomes visible within the first 60 days.
S
Sujit Mahakhud
Microsoft Sentinel Specialist · SecByte Founder
5+ years in cybersecurity · Sentinel · Threat Hunting · Cloud Security

Similar Posts

Leave a Reply