Skip to content
Welcome to "my-azure"
Simply Stay Ahead !
  • Home
  • About Me
  • About Page
  • Contact Me

About Me

Prioritize user investigations in Cloud App Security

June 21, 2019 Kirit Parmar

By Kim Kischel Microsoft

Prioritize user investigations in Cloud App Security

This week we announced a new Identity threat investigation experience, which correlates identity events from Microsoft Cloud App Security, Azure Advanced Threat Protection, and Azure Active Directory Identity Protection into a single investigation experience for security analysts and hunters alike.

If you are using Microsoft Cloud App Security, you will be able to access the new experience in the portal starting today, regardless of whether you are also using Azure Advanced Threat Protection and/or Azure Active Directory Identity Protection.*

The identity threat investigation experience combines user identity signals from on-premises and cloud services to close the gap between disparate signals in your environment and leverages state-of-the-art User and Entity Behavior Analytics (UEBA) capabilities to provide a risk score and rich contextual information for each user. It empowers security analysts to prioritize their investigations and reduce investigation times, ending the need to toggle between identity security solutions.

secops.png

Microsoft Cloud App Security – A uniquely integrated CASB

New user investigation priority for users

The Top user view in the Microsoft Cloud App Security dashboard is shifting from an investigation model that is based on the number of total alerts, to a new user investigation priority which is determined by all recent user activities and alerts that indicate an active attack or insider threat. This now helps you immediately understand which users currently represent the highest risk within your organization and should be prioritized for further investigation.

secops1 (2).png

Image 1: Cloud App Security dashboard: Top user view by investigation priority

New user page

We have also redesigned the existing user page to provide rich contextual information for how the risk score was determined and how a user compares to other across the organization. This will empower your SOC teams to address the users with the highest risk/impact ratio first and pivot from any scored activity into the deep dive alert investigation that you’re already familiar with.

secops2.png

Image 2: New user page in the Cloud App Security portal

From the new user page, you can then easily dive deeper into each one of the alerts or activities that you see on the timelines and pivot into the Cloud App Security investigation experience that you’re already familiar with.

secops3.png

Image 3: Deep dive investigation of alerts from the user timeline

The new Identity threat investigation experience further enriches the Cloud App Security portal and available investigation capabilities, giving SecOps teams correlated and weighted information to make better decisions, save time and more effectively remediate user threats and risks.

More info and feedback

  • Get started with our technical documentation today.
  • Haven’t tried Microsoft Cloud App Security yet? Start a free trial today.
  • As always, we want to hear from you! If you have any suggestions, questions, or comments, please visit us on our Tech Community page.
  • For more resources and information go to our website.

*The information available on the new user page can vary depending on the services that you are using (Azure Advanced Threat Protection, Azure AD Identity Protection)

  • Tags:
  • CASB
  • Cloud Access Security Broker
  • Identity Threats
  • Investigation
  • SecOps
  • Security Operations
  • SOC
Posted in: Advanced Threat Protection, Azure AD Identity Protection, Azure Security, Cloud Security, Identity Protection (Regular and Refreshed)

Post navigation

← Azure Sentinel
Azure AD B2C – Auth Code Flow Postman →

Search my-azure

Categories

Recent Posts

  • Ignite 2019 updates at one place December 26, 2019
  • New! Unfamiliar Sign-in Properties August 10, 2019
  • Azure AD B2C – Auth Code Flow Postman August 10, 2019
  • Prioritize user investigations in Cloud App Security June 21, 2019
  • Azure Sentinel June 19, 2019
  • Azure Security Center Documentation June 19, 2019
  • Secure DevOps kit for Azure June 19, 2019
  • Super easy way to get an access token June 15, 2019
  • Manage authentication sessions in Azure AD conditional access is now in public preview! May 1, 2019
  • Video Tutorial: ConfigMgr Part 1 thru 11 from Microsoft April 24, 2019

Recent Comments

    Archives

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Schedule

    May 2025
    M T W T F S S
     1234
    567891011
    12131415161718
    19202122232425
    262728293031  
    « Dec    
    Copyright © 2022 Welcome to "my-azure.com"