Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 0 additions & 29 deletions ATPDocs/ops-guide/ops-guide-daily.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,35 +52,6 @@ For more information, see [Work with Defender for Identity's ITDR dashboard (Pre

1. When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification.

## Investigate users with a high investigation score

**Where**: In Microsoft Defender XDR and in Microsoft Entra.

In Microsoft Defender XDR:

1. Check the **Users at risk** widget on the **Home** page or the **Entra ID users at risk** on the **Identities > Dashboard** page.

1. If you have users listed at *High risk*:

- Select **View all users** to review high risk identities in Microsoft Entra.
- Go to the **Identities** page and sort the grid to view users with high **Investigation priority** scores at the top. Select an identity to view the identity details page, including more details in the **Investigation priority** widget.

The investigation priority widget includes the calculated investigation priority score breakdown and a two-week trend for an identity, including whether the identity score is on the high percentile for that tenant.

Find more identity-related information on:

- Individual alert or incident details pages
- Device details pages
- Advanced hunting queries
- The Action center page

**Persona**: SOC analysts

For more information, see:

- [Investigate users in Microsoft Defender XDR](/microsoft-365/security/defender/investigate-users)
- [Investigate assets](../investigate-assets.md)
- [Work with Defender for Identity's ITDR dashboard (Preview)](../dashboard.md)

## Configure tuning rules for benign true positives / false positive alerts

Expand Down