Introduction to Microsoft Sentinel Entity behavior
Entity behavior, also known as User and Entity Behavior Analytics (UEBA), allows you to gather more information about the entities that have been exposed in your incident. You will not only see the other alerts that this entity is associated with, but you will also see the other activities that this entity has performed.
For more information on the various types of entities that are available, see the Further reading section.
Other information will be exposed, depending on the entity type being viewed. For instance, if you are looking at a user account, you will see information that's been gathered from Azure Active Directory.
However, to use Microsoft Sentinel Entity behavior, you must enable it. It is not enabled by default. The next section will tell you how to do just that.