Skip to main content

Predefined Investigations Page

The Predefined Investigations page in the Investigations interface provides a list of saved out-of-the-box investigations with applied filters for Applications, Computers, Groups, iNetOrgPerson, Roles and User activity reports.

Investigations interface on the Predefined Investigations page

The table displays the list of investigations with the following columns:

  • Name – The name of the investigation
  • Threat – The check mark indicates that a Threat has been configured for this investigation
  • Favorite – The check mark indicates that the investigation has been tagged as a favorite for the logged in user

Click an investigation to view it. You can run the query, modify the configuration, add a subscription, or export the report. See the Investigation Options topic for additional information on saved investigation options.

Every report generated by an investigation query displays the same type of information. See the Investigation Reports topic for additional information.

By default, these investigations are grouped in subfolders. Each subfolder page has the same table as the Predefined Investigations page, scoped to the investigations within that folder.

Applications Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Application AddedOccurs when an a Entra ID Application is addedOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Add application
Applications DeletedOccurs when an a Entra ID Application is addedOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Delete application
Applications DeletedOccurs when an a Entra ID Application is addedOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Update application

Computers Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Computer AddedCreated when a computer is addedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer DeletedCreated when a computer is deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer DisabledCreated when a computer is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer EnabledCreated when a computer is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer Password ChangedCreated when a computer password is changedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer

You can save additional investigations to this folder.

Groups Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Group AddedOccurs when a group of any type is createdTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group DeletedCreated when a group is removed / deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group Member AddedCreated when a member is added to a groupTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Group Members Added AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group Member RemovedCreated when one or more members of a group are removedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Group Members Removed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group MovedOccurs when a group is moved from one container to anotherTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Object Move AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group

You can save additional investigations to this folder.

iNetOrgPerson Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
iNetOrgPeson Account DisabledCreated when an iNetOrgPerson account is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson Account EnabledCreated when an iNetOrgPerson account is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson AddedCreated when an iNetOrgPerson User account is addedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson DeletedCreated when an iNetOrgPerson is deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson Password ChangedCreated when the password is reset or changed by an administratorTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson

You can save additional investigations to this folder.

Roles Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Add Eligible Member to RoleOccurs when an Entra ID Member is made eligible to a RoleOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Add eligible member to role
Add Member to RoleOccurs when an Entra ID Member is added to a RoleOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Add member to role
Remove Eligible Member From RoleOccurs when an Entra ID Member is made not eligible to a Role anymoreOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Remove eligible member from role
Remove Memeber from RoleOccurs when an Entra ID Member is removed from a RoleOne filter statement set: - Attribute = Event Sub-Operation - Operator = Equals - Filter = Remove member from role

Users Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
User Account DisabledCreated when a user account is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account EnabledCreated when a user account is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account LockedCreated when a user account is lockedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Locked AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account UnlockedCreated when a user account is unlockedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Unlocked AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Password ChangeCreated when a user performs a password resetThree filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Active Directory Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user AND - Attribute 3 = Perpetrator - Operator 3 = Equals - Filter 3 = nt authority\anonymous logon
User Password Reset and ChangeCreated when a user resets their password or when an administrator changes their passwordTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Primary Group ChangedCreated when a user's group is changed typically from Domain Users to another groupTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Primary Group Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user

You can save additional investigations to this folder.