You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/ops-guide/ops-guide-daily.md
-29Lines changed: 0 additions & 29 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -52,35 +52,6 @@ For more information, see [Work with Defender for Identity's ITDR dashboard (Pre
52
52
53
53
1. When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification.
54
54
55
-
## Investigate users with a high investigation score
56
-
57
-
**Where**: In Microsoft Defender XDR and in Microsoft Entra.
58
-
59
-
In Microsoft Defender XDR:
60
-
61
-
1. Check the **Users at risk** widget on the **Home** page or the **Entra ID users at risk** on the **Identities > Dashboard** page.
62
-
63
-
1. If you have users listed at *High risk*:
64
-
65
-
- Select **View all users** to review high risk identities in Microsoft Entra.
66
-
- Go to the **Identities** page and sort the grid to view users with high **Investigation priority** scores at the top. Select an identity to view the identity details page, including more details in the **Investigation priority** widget.
67
-
68
-
The investigation priority widget includes the calculated investigation priority score breakdown and a two-week trend for an identity, including whether the identity score is on the high percentile for that tenant.
69
-
70
-
Find more identity-related information on:
71
-
72
-
- Individual alert or incident details pages
73
-
- Device details pages
74
-
- Advanced hunting queries
75
-
- The Action center page
76
-
77
-
**Persona**: SOC analysts
78
-
79
-
For more information, see:
80
-
81
-
-[Investigate users in Microsoft Defender XDR](/microsoft-365/security/defender/investigate-users)
82
-
-[Investigate assets](../investigate-assets.md)
83
-
-[Work with Defender for Identity's ITDR dashboard (Preview)](../dashboard.md)
0 commit comments