Skip to content

Commit 1709e83

Browse files
committed
updates based on review comments
1 parent 19ed9b0 commit 1709e83

4 files changed

Lines changed: 5 additions & 5 deletions

File tree

articles/sentinel/identify-threats-with-entity-behavior-analytics.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ As Microsoft Sentinel ingests data from connected sources, UEBA applies:
2929
- **Behavioral modeling** to detect deviations
3030
- **Peer group analysis** and **blast radius evaluation** to assess the impact of anomalous activity
3131

32-
:::image type="content" source="media/identify-threats-with-entity-behavior-analytics/context.png" alt-text="Entity context":::
32+
:::image type="content" source="media/identify-threats-with-entity-behavior-analytics/context.png" alt-text="Diagram of concentric circles labeled User, Peers, and Organization, illustrating entity context in UEBA analysis.":::
3333

3434
UEBA assigns [risk scores](#ueba-scoring) to anomalous behaviors, taking into account the associated entities, severity of the anomaly, and context, including:
3535

@@ -80,7 +80,7 @@ This table provides an overview of the data in each of the UEBA tables:
8080
8181
This screenshot shows an example of data in the `UserPeerAnalytics` table with the eight highest-ranked peers for the user Kendall Collins. Sentinel uses the TF-IDF algorithm to normalize weights when calculating peer ranks. Smaller groups carry higher weight.
8282

83-
:::image type="content" source="./media/identify-threats-with-entity-behavior-analytics/user-peers-metadata.png" alt-text="Screen shot of user peers metadata table" lightbox="./media/identify-threats-with-entity-behavior-analytics/user-peers-metadata.png":::
83+
:::image type="content" source="./media/identify-threats-with-entity-behavior-analytics/user-peers-metadata.png" alt-text="Screenshot of user peers metadata table." lightbox="./media/identify-threats-with-entity-behavior-analytics/user-peers-metadata.png":::
8484

8585
For more detailed information about UEBA data and how to use it, see:
8686
- [UEBA reference](ueba-reference.md) for a detailed reference of all UEBA-related tables and fields.

articles/sentinel/includes/unified-soc-preview-without-alert.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.custom: "include file"
1111

1212
After **March 31, 2027**, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Microsoft Sentinel in the Azure portal will be [redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only](../overview.md#microsoft-sentinel-in-the-azure-portal-retirement-timeline). Starting in **July 2025**, many new customers are [automatically onboarded and redirected to the Defender portal](../overview.md#changes-for-new-customers-starting-july-2025).
1313

14-
If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your [transition to the Defender portal](../move-to-defender.md) to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security). For more information, see [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613).
14+
If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your [transition to the Defender portal](../move-to-defender.md) to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops/overview-unified-security). For more information, see [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613).
1515

1616

1717

articles/sentinel/includes/unified-soc-preview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,5 +12,5 @@ ms.custom: "include file"
1212
> [!IMPORTANT]
1313
> After **March 31, 2027**, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Microsoft Sentinel in the Azure portal will be [redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only](../overview.md#microsoft-sentinel-in-the-azure-portal-retirement-timeline).
1414
>
15-
> If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your [transition to the Defender portal](../move-to-defender.md) to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security).
15+
> If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your [transition to the Defender portal](../move-to-defender.md) to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops/overview-unified-security).
1616

articles/sentinel/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ Watch the [UEBA behaviors webinar](https://www.youtube.com/watch?v=SqbxmGdMP7c)
2828

2929
**New UEBA behaviors workbook**
3030

31-
To help SOC teams get value from behaviors from day one, Microsoft Sentinel now provides the **behaviors workbook** as part of the UEBA essentials solution. The workbook offers guided views and pre‑built, customizable analytics that turn rich behavioral data into actionable insights across three core SOC workflows:
31+
To help SOC teams get value from behaviors from day one, Microsoft Sentinel now provides the **behaviors workbook** as part of the UEBA essentials solution. The workbook offers guided views and prebuilt, customizable analytics that turn rich behavioral data into actionable insights across three core SOC workflows:
3232

3333
- **Overview**: High‑level metrics and trends that give SOC managers and leadership quick situational awareness
3434
- **Investigation**: Deep‑dive, entity‑centric timelines that help analysts accelerate incident response

0 commit comments

Comments
 (0)