UEBA in Microsoft Sentinel: How to Use User and Entity Behaviour Analytics Effectively
UEBA in Microsoft Sentinel: Detect Insider Threats & Compromised Accounts
📋 Table of Contents
Traditional rule-based detection catches known attack patterns — but compromised accounts and malicious insiders often operate within legitimate activity thresholds, evading signature-based detection entirely. User and Entity Behaviour Analytics (UEBA) takes a fundamentally different approach: it builds a statistical baseline of normal behaviour for every user and entity, then scores deviations from that baseline as risk signals.
Microsoft Sentinel’s built-in UEBA capability enriches every investigation with entity context, peer group comparisons, and anomaly scoring — without requiring a separate product or data pipeline.
1. What Is UEBA?
UEBA analyses behaviour patterns across multiple dimensions for users, devices, applications, and IPs:
- Temporal patterns — when does this user typically log in? What hours are normal?
- Geolocation patterns — which countries and cities are expected for this user?
- Peer group comparison — how does this user’s behaviour compare to colleagues in the same department or job role?
- Resource access patterns — what resources does this user normally access? What would be anomalous?
- Volume patterns — is the amount of data accessed or transferred within normal range?
When a user’s behaviour deviates significantly from their own baseline and from their peer group, UEBA surfaces this as an elevated risk score — giving analysts a prioritised signal to investigate.
2. How Sentinel UEBA Works
Sentinel UEBA ingests data from multiple sources simultaneously — Azure AD / Entra ID sign-in logs, Audit logs, Defender for Endpoint device events, and Microsoft 365 activity — and builds entity profiles over a learning period of 14–21 days. After the learning period, UEBA starts producing anomaly scores and insights.
Learning Period
Risk Score Range
Entity Types
Lookback Window
UEBA data flows into three key tables: BehaviorAnalytics (anomalies and risk scores), IdentityInfo (entity enrichment data), and UserAccessAnalytics (resource access patterns). These tables are free to query once UEBA is enabled — they do not incur additional ingestion charges beyond what you already pay for the source data.
3. Enabling UEBA
UEBA is enabled at the workspace level in Sentinel settings. Once activated, you configure which data sources to feed into the UEBA engine:
- Navigate to Microsoft Sentinel → Settings → Entity behaviour
- Toggle UEBA on for your workspace
- Select data sources: Azure Active Directory (sign-in + audit logs), Microsoft 365, Defender for Endpoint
- Allow 14–21 days for the initial learning period to complete
- Enable the UEBA anomalies in your Sentinel Analytics rules to surface UEBA insights as incidents
4. Key UEBA Tables
BehaviorAnalytics
The primary UEBA output table. Each row represents an anomalous activity detected for a user or entity, with a risk score and a human-readable insight explaining why the behaviour is anomalous.
| Field | Description |
|---|---|
UserPrincipalName | The user whose behaviour was analysed |
RiskScore | Score 0–10; higher = more anomalous |
InvestigationPriority | Weighted priority considering multiple signals |
ActivityType | LogOn, ResourceAccess, FileOperation, etc. |
ActivityInsights | Array of insight strings explaining why this is anomalous |
DevicesInsights | Device-related anomaly context |
IPCustomEntity | The IP address associated with the activity |
IdentityInfo
Provides enrichment data for each identity — job title, department, manager, group memberships, risk level. Updated approximately every 24 hours from Azure AD.
5. UEBA Hunting Queries
Top High-Risk Users
BehaviorAnalytics
| where TimeGenerated > ago(7d)
| where RiskScore > 7
| summarize
MaxRisk = max(RiskScore),
AvgRisk = round(avg(RiskScore), 2),
AnomalyCount = count()
by UserPrincipalName
| order by MaxRisk desc
| take 20
Anomalies with Peer Group Context
BehaviorAnalytics
| where TimeGenerated > ago(14d)
| where ActivityInsights has "UncommonForPeer"
or ActivityInsights has "FirstTimeForUser"
| extend Insights = parse_json(ActivityInsights)
| project
TimeGenerated,
UserPrincipalName,
ActivityType,
RiskScore,
IPCustomEntity,
Insights
| order by RiskScore desc
Impossible Travel via UEBA
BehaviorAnalytics
| where TimeGenerated > ago(7d)
| where ActivityInsights has "ImpossibleTravel"
| project
TimeGenerated,
UserPrincipalName,
ActivityType,
IPCustomEntity,
ActivityInsights,
InvestigationPriority
| order by InvestigationPriority desc
First-Time Access to Sensitive Resource
BehaviorAnalytics
| where TimeGenerated > ago(30d)
| where ActivityInsights has "FirstTimeForUser"
| where ActivityType == "ResourceAccess"
| summarize
FirstAccess = min(TimeGenerated),
AccessCount = count()
by UserPrincipalName, IPCustomEntity
| order by FirstAccess desc
UEBA + Incident Correlation
// Find active incidents involving high-risk UEBA users
let HighRiskUsers =
BehaviorAnalytics
| where TimeGenerated > ago(7d)
| where RiskScore > 6
| summarize MaxRisk = max(RiskScore) by UserPrincipalName;
SecurityIncident
| where TimeGenerated > ago(7d)
| where Status != "Closed"
| mv-expand RelatedEntities = parse_json(RelatedEntities)
| extend UPN = tostring(RelatedEntities.Account.AadUserId)
| join kind=inner (HighRiskUsers) on $left.UPN == $right.UserPrincipalName
| project IncidentName, Title, Severity, Status, MaxRisk, UserPrincipalName
Enrich Alerts with IdentityInfo
SecurityAlert
| where TimeGenerated > ago(24h)
| where AlertSeverity in ("High", "Medium")
| extend Entities_parsed = parse_json(Entities)
| mv-expand Entities_parsed
| extend UPN = tostring(Entities_parsed.AadUserId)
| where isnotempty(UPN)
| join kind=leftouter (
IdentityInfo
| where TimeGenerated > ago(1d)
| project AccountUPN, Department, JobTitle, RiskLevel, Manager
) on $left.UPN == $right.AccountUPN
| project TimeGenerated, AlertName, AlertSeverity, UPN, Department, JobTitle, RiskLevel
6. Entity Pages & Investigation
When you click on a user entity in a Sentinel incident, the Entity Page aggregates all UEBA data for that user into a single investigation view:
- Risk score timeline — how has the user’s risk changed over the past 30 days?
- Activity insights — all anomaly cards with explanations
- Incident history — all past incidents involving this user
- Peer group comparison — how does this user compare to colleagues?
- Alert timeline — chronological view of all alerts
Entity pages eliminate the need to manually correlate data across multiple queries during an investigation. Start every user investigation on the entity page before diving into raw log queries.
7. Best Practices
- Do not act on UEBA scores alone — use them as a prioritisation signal, not a verdict
- Correlate UEBA anomalies with other signals: threat intel, EDR alerts, DLP events
- Review the
ActivityInsightsfield in detail — it explains why the behaviour is anomalous - Set up an analytic rule that fires when
InvestigationPriority > 8to create high-priority incidents automatically - After the 21-day learning period, run the top-risk-users query weekly as a standing hunt
// Analytic rule seed: auto-create incident for very high risk scores
BehaviorAnalytics
| where TimeGenerated > ago(1h)
| where InvestigationPriority >= 8
| summarize
MaxPriority = max(InvestigationPriority),
MaxRisk = max(RiskScore),
AnomalyCount = count()
by UserPrincipalName
| where MaxPriority >= 8
