You want Microsoft Sentinel to surface user anomalies such as rare RDP logons and unusual data access patterns, and to display user insights within incidents. Your environment already streams Azure AD sign-in logs, Windows Security Events, and Microsoft 365 audit logs to Sentinel. What two actions should you perform?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel and select the identity and activity data sources to profile users and entities., Allow time for baselining and review results in the Entity behavior blade and Anomalies workbook as UEBA produces anomalies..
Why this is the answer
The correct answers are enabling UEBA and allowing time for baselining. User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel is specifically designed to detect user anomalies like rare RDP logons and unusual data access patterns by profiling user and entity behavior. After enabling UEBA and selecting relevant data sources, Sentinel requires a baselining period to learn normal behavior before it can effectively identify anomalies. The Entity behavior blade and Anomalies workbook are the correct places to review these findings. Creating a manual Fusion analytics rule is incorrect because Fusion rules are pre-built and automatically correlate alerts; you cannot manually create them to map identity fields for anomaly detection in this way. Replacing scheduled analytics rules with NRT rules is incorrect because NRT rules focus on faster detection of specific events, not on behavioral anomaly detection across users. Enabling the TAXII threat intelligence connector is incorrect as TAXII imports known threat indicators, not behavioral anomalies for users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed