We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Sentinel UEBA
Microsoft Sentinel UEBA

It costs nothing extra and most Sentinel customers have never once turned it on.

It builds a picture of how each person, machine, address and application normally behaves, then raises whatever departs from that picture. It comes with Sentinel at no additional cost, with the data landing in Log Analytics tables at standard rates. We switch it on, connect the sources it depends on, and build it into the way your analysts genuinely work rather than leaving it running in a corner.

Book a UEBA enablement reviewSee how it works
Microsoft Sentinel UEBA for US organizations
  • No extra costUEBA is included with Sentinel
  • 6 tablesWhere UEBA insights are stored
  • Two scoresThat deliberately disagree with each other
  • Top 20 peersRanked per user for peer comparison
What UEBA does

Eight things that decide whether this ever produces anything useful.

This is genuinely useful and genuinely neglected, mostly because what it produces is data you have to go and query rather than alerts arriving in a queue. Understanding what it writes and where it writes it is most of the difference between a deployment that works and one that is merely switched on.

Behavioral profiles for more than users

Machine learning constructs a moving picture of normal behavior for each person, machine, address, application and other entity, then finds what departs from it by comparing today activity against the baseline it has learned. Three use cases are named: accounts that have been taken over, attacks from inside, and movement sideways through the estate.

Peer comparison, weighted intelligently

One table ranks each person twenty closest peers, worked out from security group membership, mailing lists and other associations, weighted so that smaller groups count for more. Belonging to a specialized group of six says a great deal about somebody. Belonging to the group containing all staff says nothing at all.

Two scores measuring different things

There are two scores and they are not the same thing. Investigation priority runs from zero to ten, lives in the behavior analytics table, is calculated close to real time and measures how unusual a single event was. Anomaly score runs from zero to one, lives in the anomalies table, is processed in batches and measures behavior across many events together.

Blast radius as part of the assessment

Alongside the behavioral modeling it also compares people against their peers and works out the blast radius, meaning what the anomalous activity could actually reach. That is precisely what separates an odd action by somebody with almost no access from the identical action by somebody who can open every system in the building.

Identity context from both directories

One table holds detailed profiles of people, devices and groups, assembled from Entra and, optionally, from the directory on your own servers by way of Defender for Identity. In a hybrid estate that second source is exactly what turns a cloud-only picture into a complete one.

The behaviors layer is a separate switch

The behaviors layer is a separate thing entirely, enabled on its own rather than arriving with the rest, and its two tables do not exist at all until somebody switches it on. Querying for a table that was never created is among the most common early confusions here.

Queries you do not have to write

There is a solution package containing dozens of ready-written hunting queries, curated and kept current by Microsoft security researchers, covering anomaly detection across Azure, AWS, Google Cloud and Okta. Installing it is how a team gets something useful within days rather than months.

Embedded experiences in the Defender portal

A widget on the home page, behavioral context shown on each user page with automatic tagging where something unusual appears, a panel showing the three highest anomalies from the past month, anomaly queries launchable straight from an incident graph, and a banner in hunting prompting a join to the anomalies table.

The detail that confuses analysts

The two scores will contradict each other, and that is the design behaving exactly as intended.

There is a worked example for this, and understanding it stops a team deciding that one of the two numbers must be broken.

  • Somebody carries out an Azure operation for the first time. Investigation priority comes back high, because it has never happened before. Anomaly score comes back low, because people doing something in Azure for the first time is entirely ordinary and carries no particular risk. Both numbers are right. They are answering different questions.
  • Investigation priority sits in the behavior analytics table, runs from zero to ten, is worked out close to real time for each event, and blends how rare the person, the device and the country are with a time series measure catching patterns like a sudden spike in failed sign-ins.
  • Anomaly score sits in the anomalies table, runs from zero to one, is processed in batches at the level of behavior rather than individual events, and comes from a detector trained on the telemetry in your own workspace. Its purpose is spotting patterns and aggregated anomalies across time, not triaging a single event this afternoon.
  • Some correlation is expected, and a high anomaly score frequently does line up with a high investigation priority, though by no means always. Each carries insight the other does not, which is exactly why using only one of them throws away half of what you have.
Ask us to build UEBA into your triage
How we approach it

Four things that turn UEBA from enabled into used.

This never competes for attention in an alert queue, which is precisely why it gets forgotten. Everything below is about putting its output where analysts are already looking.

We install the queries rather than writing them

The solution package carries dozens of ready-written hunting queries, curated and maintained by Microsoft researchers, covering Azure, AWS, Google Cloud and Okta. Building anything equivalent yourself takes months and ends up worse than what you could have installed on the first afternoon.

We teach the two scores as two different tools

Investigation priority runs zero to ten, close to real time, measuring how unusual a single event was, and it exists for triage. Anomaly score runs zero to one, in batches, measuring behavior across many events, and it exists for spotting patterns. Teams that treat the two as one number invariably conclude that one of them must be broken.

We check which tables you actually have

What gets covered depends on which connectors are actually running, and the behaviors layer tables do not exist at all unless somebody enabled that separately. Half an hour spent confirming which tables hold rows saves an analyst an extremely frustrating afternoon querying one that was never going to return anything.

We connect the on-premises identity source

The identity table is assembled from Entra and, optionally, from the directory on your own servers by way of Defender for Identity. In a hybrid estate, leaving out that second source produces profiles missing precisely the context that matters for detecting movement sideways, which happens to be one of the three named use cases.

How an engagement runs

Four phases across roughly five weeks.

Turning it on is a single switch. The actual work is connecting the sources it depends on and threading it into how analysts already triage, because what it produces is data to query rather than a queue to work through.
  1. 01
    Week 1

    Enable and connect the sources it depends on

    Switched on, with the sources that matter connected: Entra, Defender for Identity and Office 365 among them. How much lands in the behavior analytics table depends entirely on which connectors are running, so this step alone decides how much of your estate gets profiled at all.

    • UEBA enabled in the workspace
    • Entra ID, Defender for Identity, and Office 365 connected
    • Multicloud sources connected where they exist
    • Behaviors layer decision recorded
  2. 02
    Week 2

    Install UEBA Essentials and let baselines form

    The solution package installed, bringing dozens of ready-written hunting queries maintained by Microsoft researchers, with anomaly detection reaching across Azure, AWS, Google Cloud and Okta. The baselines need time to form and the queries need data underneath them before either is worth reading.

    • UEBA Essentials solution installed
    • Pre-built hunting queries available to analysts
    • IdentityInfo populated from both directories where hybrid
    • Table availability confirmed per connected source
  3. 03
    Weeks 3 to 4

    Build UEBA into the triage workflow

    This is the phase that determines whether any of it gets used. Investigation priority applied while triaging individual events, anomaly score used for looking at patterns over weeks, and hunting queries joined to the anomalies table so that every investigation carries behavioral context without anybody remembering to add it.

    • Investigation priority incorporated into triage
    • Anomaly score used in periodic pattern review
    • Existing hunting queries enriched with Anomalies joins
    • Analyst guidance on when each score applies
  4. 04
    Week 5

    Use the embedded experiences and hand over

    The portal experiences adopted on purpose rather than discovered by accident: the home page widget, the behavioral context on user pages, the three highest anomalies from the past month, and the anomaly queries launchable from an incident graph. Then a review rhythm, so that six months later somebody is still opening it.

    • Defender portal UEBA experiences demonstrated to analysts
    • Incident graph anomaly queries adopted
    • Periodic anomaly pattern review scheduled
    • Handover with query examples for the team
Where this matters

Six situations where behavioral context changes the answer.

The recurring shape is an event that looks perfectly fine on its own and looks entirely different once you know what that person normally does and what everybody in the same role does.

A business investigating a possibly compromised account

Accounts that have been taken over are one of the three named use cases. The real question is whether this activity is normal for this particular person, and a behavioral profile alongside a peer comparison answers that directly. A threshold rule can only tell you whether something crossed a number somebody chose in a meeting.

An organization with an insider concern

Insider attacks are the second named use case, and they are the hardest to detect with rules because the activity is authorized. Deviation from an individual baseline, and from what their peer group does, is the signal that a permission check cannot produce.

A company tracking lateral movement

The third named use case, and the one that most depends on complete identity context. Where the estate is hybrid, IdentityInfo built from Entra ID plus on-premises Active Directory through Defender for Identity is what makes the movement visible across the boundary.

A regulated firm prioritizing a large alert queue

Investigation priority ranges 0 to 10 and combines entity rarity with time series patterns such as spikes in failed sign-ins. Used during triage it gives a defensible order of work, which is more useful than severity alone when everything is labeled high.

An operator with a multicloud footprint

The UEBA Essentials solution includes multicloud anomaly detection queries across Azure, AWS, Google Cloud Platform, and Okta. For estates that ended up multicloud through acquisition, that is behavioral coverage across all of it without writing separate detection for each.

A team that wants more from Sentinel without more spend

UEBA is included with Sentinel at no extra cost, with data stored in Log Analytics tables under standard pricing. For an organization already paying for Sentinel and looking for more value from it, enabling and using UEBA is among the highest return actions available.

Three positions

How US organizations use behavioral analytics.

The middle column describes most deployments: switched on during a project two years ago, tables quietly filling with data ever since, and nobody querying a single row of it because nothing ever appears in the alert queue to prompt them.
Behavioral baselines exist
Enabled and built into triageYes
Enabled, unusedYes
Never enabledNo
Investigation priority used in triage
Enabled and built into triageYes
Enabled, unusedNo
Never enabledNot applicable
Anomaly patterns reviewed
Enabled and built into triagePeriodically
Enabled, unusedNo
Never enabledNot applicable
Peer comparison available
Enabled and built into triageYes
Enabled, unusedYes, unused
Never enabledNo
Hunting queries enriched
Enabled and built into triageAnomalies joined
Enabled, unusedNo
Never enabledNot applicable
Pre-built queries installed
Enabled and built into triageUEBA Essentials
Enabled, unusedNo
Never enabledNo
Hybrid identity context
Enabled and built into triageVia Defender for Identity
Enabled, unusedCloud only
Never enabledNone
Insider risk signal
Enabled and built into triagePresent
Enabled, unusedPresent, unread
Never enabledAbsent
Lateral movement signal
Enabled and built into triagePresent
Enabled, unusedPresent, unread
Never enabledAbsent
Additional cost
Enabled and built into triageNone
Enabled, unusedNone
Never enabledNone
Feature
Enabled and built into triage
Enabled, unused
Never enabled
Behavioral baselines exist
YesYesNo
Investigation priority used in triage
YesNoNot applicable
Anomaly patterns reviewed
PeriodicallyNoNot applicable
Peer comparison available
YesYes, unusedNo
Hunting queries enriched
Anomalies joinedNoNot applicable
Pre-built queries installed
UEBA EssentialsNoNo
Hybrid identity context
Via Defender for IdentityCloud onlyNone
Insider risk signal
PresentPresent, unreadAbsent
Lateral movement signal
PresentPresent, unreadAbsent
Additional cost
NoneNoneNone
Where UEBA writes its data

Six tables and what each is for.

Analysts routinely join across these to follow anomalous behavior from one end to the other. Knowing which table holds what removes most of the friction in ever getting started.

Table

IdentityInfo

What it holds
Detailed profiles of people, devices and groups drawn from Entra and, optionally, your own directory

Table

BehaviorAnalytics

What it holds
Deviations from baseline with prioritization scores, enriched with geolocation and threat intelligence

Table

UserPeerAnalytics

What it holds
Peer groups worked out on the fly, with the closest twenty ranked per person

Table

Anomalies

What it holds
Events identified as anomalous, supporting detection and investigation

Table

SentinelBehaviorInfo

What it holds
Plain language summaries of who did what to whom, mapped to the recognized attack techniques

Table

SentinelBehaviorEntities

What it holds
Profiles covering the files, processes, devices and people caught up in a detected behavior

Table

Behaviors layer tables

What it holds
Only created if you enable the behaviors layer separately

Table

InvestigationPriority field

What it holds
Behavior analytics table, zero to ten, close to real time, one event at a time

Table

AnomalyScore field

What it holds
In Anomalies, 0 to 1, batch, behavior across multiple events

Table

Coverage of these tables

What it holds
Depends on which connectors are enabled
TableWhat it holds
IdentityInfoDetailed profiles of people, devices and groups drawn from Entra and, optionally, your own directory
BehaviorAnalyticsDeviations from baseline with prioritization scores, enriched with geolocation and threat intelligence
UserPeerAnalyticsPeer groups worked out on the fly, with the closest twenty ranked per person
AnomaliesEvents identified as anomalous, supporting detection and investigation
SentinelBehaviorInfoPlain language summaries of who did what to whom, mapped to the recognized attack techniques
SentinelBehaviorEntitiesProfiles covering the files, processes, devices and people caught up in a detected behavior
Behaviors layer tablesOnly created if you enable the behaviors layer separately
InvestigationPriority fieldBehavior analytics table, zero to ten, close to real time, one event at a time
AnomalyScore fieldIn Anomalies, 0 to 1, batch, behavior across multiple events
Coverage of these tablesDepends on which connectors are enabled
How an engagement runs

Five steps, and the last two are about habits.

The technical enablement is short. Making behavioral context part of how analysts work is what determines whether the capability is still being used in six months.
  1. 1

    Enable UEBA and connect the key sources

    Microsoft Entra ID, Defender for Identity, and Office 365 are named as key sources, and coverage in the behavioral tables depends on which connectors are enabled. For hybrid estates, Defender for Identity is what brings on-premises Active Directory context into the identity profiles.

  2. 2

    Decide on the behaviors layer explicitly

    It is a separate capability enabled independently, and the SentinelBehaviorInfo and SentinelBehaviorEntities tables only exist if you enable it. Those tables translate raw logs into who did what to whom summaries with natural language explanations and MITRE ATT&CK mappings.

  3. 3

    Install UEBA Essentials

    Dozens of pre-built hunting queries curated and maintained by Microsoft security experts, including multicloud anomaly detection across Azure, AWS, Google Cloud Platform, and Okta. This is the difference between having UEBA data and being able to use it in the first week.

  4. 4

    Put investigation priority into the triage routine

    A 0 to 10 near real time score of how unusual a single event is, combining entity rarity with time series patterns. Used during triage it gives an order of work grounded in behavior rather than in a severity label everything shares.

  5. 5

    Add a periodic anomaly pattern review

    Anomaly score is processed in batches at the level of behavior across many events, so it answers a different question on a completely different rhythm. A scheduled review of the patterns, plus hunting queries joined to the anomalies table, is the only way that half of the capability ever gets used.

Straight answers

What organizations ask about Sentinel UEBA.

No. It is included with Sentinel at no additional cost. The data lands in Log Analytics tables and follows the standard pricing, so what you pay for is the ingestion you were already paying for rather than any separate charge for the capability itself.

It constructs a moving picture of normal behavior for each person, machine, address, application and other entity, then finds departures from it by comparing today activity against those baselines. Three categories are named specifically: accounts taken over, attacks from inside, and movement sideways through the estate.

Entra, Defender for Identity and Office 365 are named as the sources that matter most. What ends up in the behavioral tables depends on which connectors are running, so the answer for your environment is decided entirely by what somebody has already connected.

Almost certainly the behaviors layer. It is a separate capability, enabled on its own rather than arriving with the rest, and its two tables are only created in your workspace once somebody switches it on. Query them before that and you get nothing back, which looks exactly like a fault.

Investigation priority lives in the behavior analytics table, runs zero to ten, is calculated close to real time per event, and measures how unusual that one event was. Anomaly score lives in the anomalies table, runs zero to one, is processed in batches at the level of behavior, and measures anomalous conduct taken across many events together.

By design, and there is a worked example. Somebody performs an Azure operation for the first time. Investigation priority comes back high because it has never happened before. Anomaly score comes back low because occasional first-time Azure actions are entirely common and carry no particular risk. Both numbers are correct.

It blends how rare each entity is, meaning the person, the device and the country, with a time series measure catching abnormal patterns such as a sudden spike in failed sign-ins. That combination is why it reacts so quickly to something happening for the first time.

The peer analytics table ranks each person twenty closest colleagues, worked out from security group membership, mailing lists and other associations, weighted so that smaller groups count for considerably more. Sitting in a specialized group of six tells you far more about somebody than sitting in the group that contains everyone in the company.

Not strictly required, and in a hybrid estate it makes a genuine difference. The identity table is built from Entra and, optionally, from the directory on your own servers by way of Defender for Identity. Leave that out and the profiles are cloud-only, which weakens precisely the sideways-movement detection this is best at.

A package containing dozens of ready-written hunting queries, curated and kept current by Microsoft researchers, with anomaly detection reaching across Azure, AWS, Google Cloud and Okta. Installing it is how a team starts getting value out of this data quickly instead of writing queries from a blank page.

In several places. A widget on the home page, behavioral context in the side panels and on the overview tab of each user page with automatic tagging when something unusual appears, a panel showing the three highest anomalies from the past month, and anomaly queries launchable straight out of an incident graph.

Its value lies in being data you query and context inside an investigation rather than in being another queue to work. That is exactly why it gets forgotten wherever nothing puts it in front of an analyst, and why building it into triage and hunting matters far more than switching it on did.

Yes, and the portal nudges you toward it. Write a hunting or custom detection query touching any of these tables and a banner appears suggesting a join to the anomalies table, which is what puts behavioral context into the investigation.

It gathers related events out of enormous volumes of raw log data and assembles them into structured behaviors describing who did what to whom, with plain language explanations, mappings to recognized attack techniques, and each entity role identified. Fragmented log lines become coherent objects you can hunt across and write detections against.

It supplies the behavioral signal side. Insider attacks are one of the three use cases Microsoft names, and deviation from individual and peer baselines is evidence a permission review cannot produce. For a formal insider risk program, Microsoft Purview Insider Risk Management addresses the case management side; UEBA gives your SOC the behavioral telemetry underneath. Your compliance advisors own policy; we configure the controls.

Each engagement is scoped individually around which sources are connected and how much work is needed to weave it into triage. The step that costs nothing: go and check whether this is even enabled in your workspace. A large share of Sentinel customers discover it is not, having never switched on something that was free all along.

Context about consequence rather than probability. Alongside the behavioral modeling it compares people against their peers and evaluates the blast radius to work out what the anomalous activity could actually reach. That is what separates an odd action by somebody with almost no access from the identical action by somebody who can open every system you own.

There is a published reference listing the anomalies the machine learning engine detects, and the solution package ships hunting queries built around exactly those. Reading that reference alongside a list of your own connected sources is the quickest way to establish which detections your data can genuinely support.

Yes. It is integrated natively into both, with the experiences embedded rather than linked: the home page widget, the context and tagging on user pages, the anomaly queries reachable from an incident graph, and the prompt in advanced hunting suggesting a join to the anomalies table.
Enablement check

Fifteen questions about your own UEBA position.

Everything hinges on the first question. A large share of Sentinel customers answer no to it, having never switched on a capability that costs them nothing.

Enablement

  • Is UEBA enabled at all?
    It is included at no extra cost.
  • Is Entra ID connected?
    A key source for profiles.
  • Is Defender for Identity connected?
    It brings on-premises AD context.
  • Is Office 365 connected?
    Named as a key source.
  • Have we enabled the behaviors layer?
    Separate switch, separate tables.

Data

  • Is IdentityInfo populated?
    From Entra ID and optionally AD.
  • Does BehaviorAnalytics have data?
    It depends on connectors.
  • Is UserPeerAnalytics building peer groups?
    Top 20 per user.
  • Are multicloud sources connected?
    AWS, GCP, and Okta are covered.
  • Have we installed UEBA Essentials?
    Dozens of pre-built queries.

Use

  • Do analysts use investigation priority?
    For single event triage.
  • Does anybody review anomaly score patterns?
    For behavior over time.
  • Do hunting queries join the Anomalies table?
    The portal prompts for this.
  • Do we use the incident graph anomaly queries?
    Built in, one click.
  • Does anybody look at the UEBA widget?
    On the Defender home page.
Related reading

The pages around this one.

Sentinel analytics rules

The rule-based half of detection, alongside behavioral analytics.

Learn more

KQL threat hunting

Querying the tables UEBA populates.

Learn more

Microsoft Purview

The compliance side of the same platform, including insider risk management.

Learn more
Next step

Check whether UEBA is enabled in your Sentinel workspace.

It costs nothing extra and a large share of customers have never turned it on. If it is off, you are already paying to ingest the very data it would have profiled while receiving none of the behavioral context that data could produce.

Book a UEBA enablement reviewSee Microsoft Sentinel services

Related Services

Explore more solutions that work great with this service

Microsoft Sentinel Analytics Rules

Sentinel detection engineering for US organizations: every enabled

Learn more

KQL Threat Hunting Enablement

Advanced hunting and KQL enablement for US security teams: permission

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

Microsoft Sentinel Data Connectors

Ingestion reviewed, connectors migrated, costs controlled

Learn more

SOC-as-a-Service

24/7 security operations delivered as a service

Learn more

Microsoft Purview

Data governance and compliance solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA