0
(0)

Note

The Defender for Identity features explained on this page are also accessible using the new portal.

Activities detected by Defender for Identity on your network can be searched and filtered for easy drill-down and organization during your research and investigation into security alerts.

From the Defender for Identity timeline, select any entity in your network (DC, machine, or user) as the filter access point. Next, select to filter by the Security AlertActivity type, or any combination. Once the filter is applied, the threat timeline of the entity is updated with the filtered information. Your filtered alerts and activities can also be downloaded to continue your investigation or tracking in other tools.

Filter alerts and activities.

To filter alerts and activities:

  1. Select the entity to investigate from the Defender for Identity timeline.
  2. Click Filter by, then select the alerts and/or activities to filter.
  3. Click Apply. The entity timeline is updated according to the filters you selected.
  4. To download the filtered activities, click Download activities and select the date range for your download report.
  5. To reset the entity timeline to display all alerts and activities, click Reset or close the filter.

Source : Official Microsoft Brand
Editor by : BEST Antivirus KBS Team

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

(Visited 9 times, 1 visits today)