Skip to content

Commit 1bc9030

Browse files
Update ops-guide-daily.md
remove section on Investigation Priority Score as the feature has been deprecated by MDA.
1 parent e2a963f commit 1bc9030

File tree

1 file changed

+0
-29
lines changed

1 file changed

+0
-29
lines changed

ATPDocs/ops-guide/ops-guide-daily.md

Lines changed: 0 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -52,35 +52,6 @@ For more information, see [Work with Defender for Identity's ITDR dashboard (Pre
5252

5353
1. When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification.
5454

55-
## Investigate users with a high investigation score
56-
57-
**Where**: In Microsoft Defender XDR and in Microsoft Entra.
58-
59-
In Microsoft Defender XDR:
60-
61-
1. Check the **Users at risk** widget on the **Home** page or the **Entra ID users at risk** on the **Identities > Dashboard** page.
62-
63-
1. If you have users listed at *High risk*:
64-
65-
- Select **View all users** to review high risk identities in Microsoft Entra.
66-
- Go to the **Identities** page and sort the grid to view users with high **Investigation priority** scores at the top. Select an identity to view the identity details page, including more details in the **Investigation priority** widget.
67-
68-
The investigation priority widget includes the calculated investigation priority score breakdown and a two-week trend for an identity, including whether the identity score is on the high percentile for that tenant.
69-
70-
Find more identity-related information on:
71-
72-
- Individual alert or incident details pages
73-
- Device details pages
74-
- Advanced hunting queries
75-
- The Action center page
76-
77-
**Persona**: SOC analysts
78-
79-
For more information, see:
80-
81-
- [Investigate users in Microsoft Defender XDR](/microsoft-365/security/defender/investigate-users)
82-
- [Investigate assets](../investigate-assets.md)
83-
- [Work with Defender for Identity's ITDR dashboard (Preview)](../dashboard.md)
8455

8556
## Configure tuning rules for benign true positives / false positive alerts
8657

0 commit comments

Comments
 (0)