Skip to content

Commit 3f974f8

Browse files
authored
Merge pull request #1477 from diannegali/docs-editor/investigate-users-1727439254
Update investigate-users.md
2 parents dc492b1 + ba3be1d commit 3f974f8

File tree

2 files changed

+11
-7
lines changed

2 files changed

+11
-7
lines changed

defender-xdr/investigate-users.md

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -10,16 +10,16 @@ author: diannegali
1010
manager: dansimp
1111
audience: ITPro
1212
ms.collection:
13-
- m365-security
14-
- tier2
15-
- usx-security
13+
- m365-security
14+
- tier2
15+
- usx-security
1616
ms.topic: conceptual
1717
search.appverid: met150
1818
ms.custom: seo-marvel-jun2020
19-
ms.date: 03/29/2024
19+
ms.date: 09/30/2024
2020
appliesto:
21-
- Microsoft Defender XDR
22-
- Microsoft Sentinel in the Microsoft Defender portal
21+
- Microsoft Defender XDR
22+
- Microsoft Sentinel in the Microsoft Defender portal
2323
---
2424

2525
# User entity page in Microsoft Defender
@@ -56,8 +56,10 @@ The user page shows the Microsoft Entra organization as well as groups, helping
5656

5757
### Entity details
5858

59-
The **Entity details** panel on the left side of the page provides information about the user, such as the Microsoft Entra identity risk level, the number of devices the user is signed in to, when the user was first and last seen, the user's accounts, groups that the user belongs to, contact information, and more. You see other details depending on the integration features you enabled.
59+
The **Entity details** panel on the left side of the page provides information about the user, such as the Microsoft Entra identity risk level, the insider risk severity level (Preview), the number of devices the user is signed in to, when the user was first and last seen, the user's accounts, groups that the user belongs to, contact information, and more. You see other details depending on the integration features you enabled.
6060

61+
> [!NOTE]
62+
> (Preview) Microsoft Defender XDR users with access to [Microsoft Purview Insider Risk Management](/purview/insider-risk-management-solution-overview) can now see a user's insider risk severity and gain insights on a user's suspicious activities in the user page. Select the **insider risk severity** under Entity details to see the risk insights about the user.
6163
### Visual view of incidents and alerts
6264

6365
This card includes all incidents and alerts associated with the user entity, grouped by severity.

defender-xdr/whats-new.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -97,6 +97,8 @@ You can also get product updates and important notifications through the [messag
9797

9898
## May 2024
9999

100+
- (Preview) Security analysts can now investigate a user's insider risk in the Microsoft Defender portal with **insider risk severity and insights** available for Microsoft Defender XDR users with provisioned access to Microsoft Purview Insider Risk Management. See the [entity details in the user page](investigate-users.md#entity-details) for more information.
101+
100102
- (GA) The endpoint security policies page is now available in multitenant management in Microsoft Defender XDR. Create, edit, and delete security policies for your tenants' devices from the **Endpoint security policies** page. For more information, see [Endpoint security policies in multitenant management](mto-endpoint-security-policy.md).
101103

102104
- Create alert tuning rules using **Alert severity** and **Alert title** values as conditions. Alert tuning can help you streamline the alert queue, saving triage time by hiding or resolving alerts automatically, each time a certain expected organizational behavior occurs, and rule conditions are met. For more information, see [Tune an alert](investigate-alerts.md#tune-an-alert).

0 commit comments

Comments
 (0)