Use the Identity Behavioral Insights capability to create an identity activity analysis when you suspect an identity has been compromised and want to investigate what changed, when, and which objects were affected.
Before you begin
Common Pre-requisites
Your Druva tenant must have the Identity ARR SKU enabled. To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.
The identity provider for the identity you want to investigate must be connected to Druva (Entra ID, Microsoft Active Directory, or Okta).
You must have the Cloud Admin or Cloud Admin (Read-only) role.
Cloud Key Management System (KMS) must be configured for all identity providers - Okta, Entra ID, and Microsoft Active Directory.
Microsoft Active Directory Pre-requisites for Identity Behavioral Insights
Ensure that the following Active Directory pre-requisites are met before you begin using Identity Resiliency feature for Microsoft Active Directory identities.
You must have upgraded to the latest Microsoft Active Directory agent Version : 2.0.0::r1080200
For some events, audit policy is not enabled by default. You have to enable it manually.
Here is the list of events and commands to enable auditing for them:
Enable Application Group Management
auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
Enable Distribution Group Management
auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
Enable Directory Service Changes
auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
Enable Directory Service Access
auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
Entra ID Pre-requisites for Identity Behavioral Insights
Ensure that you have reinstalled the Druva Entra ID app before enabling the Identity Resiliency feature. For more information, see Reinstall Entra ID app.
Navigate to Identity Behavioral Insights
From the Cloud Platform console dashboard, navigate to Global Navigation icon > Cyber Resiliency > Identity Resiliency.
The Identity Behavioral Insights page opens with the New Analysis form at the top and a Recent Analyses table below.
The Recent Analyses table displays list of historical or already created identity activity analyses.
đĄTip: Select Explore Identity Resiliency Features near the page title to open the Get Started with Identity Behavioural Insights guide, which walks through the three-step workflow (Define Scope â Investigate â Resolve).
Create a new identity activity analysis
Under New Analysis, select an Identity Provider: Entra ID, Active Directory, or Okta.
Only providers connected to your tenant appear as options.
In the Identity field, type at least three characters of the user's name or service principal's name. Select the identity from the suggestions that appear. For Active Directory and Okta, you also need to select the Domain.
Select a Time Range:
Last 24 hours: Events from the past 24 hours
Last 7 days: Events from the past 7 days
14 days: Events from the past 14 days
Custom Time Period: A date range you specify. For a custom range,
The window cannot exceed 30 days.
The start date can go back up to 12 months from today.
The earliest available start date is one month before Identity Resiliency became available in your region.
Select Analyze Identity Activity.
When the analysis is complete, the results page opens automatically. See Review Identity Activity Results <Link>
Reopen a saved identity activity analysis
All analyses are saved automatically. To reopen one:
Scroll to Recent Analyses on the Identity Activity Analysis page and click the Primary Identity to view the analysis.
Or, from any results page, click Analysis History, find the analysis, and select Open Analysis.
Modify an existing identity activity analysis
To change the identity, provider, or time range for an open analysis, select New Analysis and update the fields. Selecting Analyze Identity Activity re-runs the analysis with the new parameters.
Next Steps
Build a guided recovery plan based on the results



