User and Entity Behavior Analytics
Microsoft Sentinel UEBA identifies threats by building behavioral baselines for users and entities, then surfacing anomalies and contextual insights for investigations.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Supported | Reference |
| Graph | Gap | No supported Microsoft Graph configuration surface is recorded for this capability yet. |
| ARM | Gap | UEBA configuration has partial workspace/provider settings coverage; model explicit settings with REST/azapi after validating current tenant support. |
| Bicep | Gap | Use REST/azapi for currently supported UEBA settings rather than a dedicated Bicep resource. |
| Terraform | Gap | No dedicated azurerm resource is recorded for UEBA configuration. Use REST/azapi if automating tenant-specific settings. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |