diff --git a/ATPDocs/investigate-assets.md b/ATPDocs/investigate-assets.md index 86dd1b3592..bb2e773ba6 100644 --- a/ATPDocs/investigate-assets.md +++ b/ATPDocs/investigate-assets.md @@ -57,7 +57,7 @@ When you investigate a specific identity, you'll see the following details on an |Identity details page area |Description | |---------|---------| -|[Overview tab](/microsoft-365/security/defender/investigate-users#overview) | General identity data, such as the Microsoft Entra identity risk level, the number of devices the user is signed in to, when the user was first and last seen, the user's accounts and more important information.

Use the **Overview** tab to also view graphs for incidents and alerts, the investigation priority score, an organizational tree, entity tags, and a scored activity timeline. | +|[Overview tab](/microsoft-365/security/defender/investigate-users#overview) | General identity data, such as the Microsoft Entra identity risk level, the number of devices the user is signed in to, when the user was first and last seen, the user's accounts and more important information.

Use the **Overview** tab to also view graphs for incidents and alerts, an organizational tree, entity tags, and a scored activity timeline. | |[Incidents and alerts](/microsoft-365/security/defender/investigate-users#incidents-and-alerts) | Lists active incidents and alerts involving the user from the last 180 days, including details like alert severity and the time the alert was generated. | |[Observed in organization](/microsoft-365/security/defender/investigate-users#observed-in-organization) | Includes the following sub-areas:
- **Devices**: The devices that the identity signed in to, including most and least used in the last 180 days.
- **Locations**: The identity's observed locations over the last 30 days.
- **Groups**: All observed on-premises groups for the identity.
- **Lateral movement paths** - all profiled lateral movement paths from the on-premises environment. | |[Identity timeline](/microsoft-365/security/defender/investigate-users#timeline) | The timeline represents activities and alerts observed from a user's identity from the last 180 days, unifying identity entries across Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Defender for Endpoint.

Use the timeline to focus on activities a user performed or were performed on them in specific timeframes. Select the default **30 days** to change the time range to another built-in value, or to a custom range. |