Defender-BehaviorEntities

ActionTypeTitleSampleRule
anyBehavior entitiesYN

any: Behavior entities

#
Table
BehaviorEntities

Example Event #

{
  "AccountDomain": "example.onmicrosoft.com",
  "AccountName": "adminuser",
  "AccountObjectId": "11111111-1111-1111-1111-111111111111",
  "AccountUpn": "adminuser@example.onmicrosoft.com",
  "ActionType": "UnusualAdditionOfCredentialsToAnOauthApp",
  "AdditionalFields": {
    "Type": "account",
    "$id": "501",
    "RbacScopes": {
      "ScopesPerType": {
        "DiscoveryStreamId": {
          "Scopes": []
        },
        "RiskCategory": {
          "Scopes": [
            "0"
          ]
        },
        "UserGroupId": {
          "Scopes": []
        },
        "Workloads": {
          "Scopes": [
            "Itp"
          ]
        },
        "AppstanceId": {
          "Scopes": [
            "11161"
          ]
        }
      }
    },
    "Name": "adminuser",
    "AadUserId": "11111111-1111-1111-1111-111111111111",
    "UPNSuffix": "example.onmicrosoft.com",
    "IsAnonymized": false,
    "CloudAppAccountId": "11161|0|11111111-1111-1111-1111-111111111111",
    "Role": 0
  },
  "BehaviorId": "oa315ae74246f1b5d48409bbf90abc388d4f94805893b19e4c77013e797308e9b8",
  "Categories": [
    "Persistence"
  ],
  "DataSources": [
    "Microsoft Cloud App Security"
  ],
  "DetectionSource": "Cloud App Security",
  "EntityRole": "Impacted",
  "EntityType": "User",
  "ServiceSource": "Microsoft Cloud App Security",
  "Timestamp": "2026-07-25T20:41:17.837Z"
}

References #