Skip to main content

Create an identity activity analysis

Use this article to understand how to create identity activity analysis from Identity Behavioural Insights UI.

Use the Identity Behavioral Insights capability to create an identity activity analysis when you suspect an identity has been compromised and want to investigate what changed, when, and which objects were affected.

Before you begin

Common Pre-requisites

  • Your Druva tenant must have the Identity ARR SKU enabled. To access Identity Resiliency feature, customers must possess an Identity workload license. We have introduced a new Identity ARR SKU, to be purchased separately as a standalone offering or as a bundle. Contact your Account Manager or raise a case via Dru Assist to enable this feature.

  • The identity provider for the identity you want to investigate must be connected to Druva (Entra ID, Microsoft Active Directory, or Okta).

  • You must have the Cloud Admin or Cloud Admin (Read-only) role.

  • Cloud Key Management System (KMS) must be configured for all identity providers - Okta, Entra ID, and Microsoft Active Directory.

Microsoft Active Directory Pre-requisites for Identity Behavioral Insights

Ensure that the following Active Directory pre-requisites are met before you begin using Identity Resiliency feature for Microsoft Active Directory identities.

Here is the list of events and commands to enable auditing for them:

  • Enable Application Group Management

    auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable

  • Enable Distribution Group Management

    auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
  • Enable Directory Service Changes

    auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable

  • Enable Directory Service Access

    auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable

Entra ID Pre-requisites for Identity Behavioral Insights

  • Ensure that you have reinstalled the Druva Entra ID app before enabling the Identity Resiliency feature. For more information, see Reinstall Entra ID app.

Navigate to Identity Behavioral Insights

  1. From the Cloud Platform console dashboard, navigate to Global Navigation icon > Cyber Resiliency > Identity Resiliency.

  2. The Identity Behavioral Insights page opens with the New Analysis form at the top and a Recent Analyses table below.

The Recent Analyses table displays list of historical or already created identity activity analyses.


💡Tip: Select Explore Identity Resiliency Features near the page title to open the Get Started with Identity Behavioural Insights guide, which walks through the three-step workflow (Define Scope → Investigate → Resolve).


Create a new identity activity analysis

  1. Under New Analysis, select an Identity Provider: Entra ID, Active Directory, or Okta.

    Only providers connected to your tenant appear as options.

  2. In the Identity field, type at least three characters of the user's name or service principal's name. Select the identity from the suggestions that appear. For Active Directory and Okta, you also need to select the Domain.

  3. Select a Time Range:

    1. Last 24 hours: Events from the past 24 hours

    2. Last 7 days: Events from the past 7 days

    3. 14 days: Events from the past 14 days

    4. Custom Time Period: A date range you specify. For a custom range,

      1. The window cannot exceed 30 days.

      2. The start date can go back up to 12 months from today.

      3. The earliest available start date is one month before Identity Resiliency became available in your region.

  4. Select Analyze Identity Activity.

When the analysis is complete, the results page opens automatically. See Review Identity Activity Results <Link>

Reopen a saved identity activity analysis

All analyses are saved automatically. To reopen one:

  • Scroll to Recent Analyses on the Identity Activity Analysis page and click the Primary Identity to view the analysis.

  • Or, from any results page, click Analysis History, find the analysis, and select Open Analysis.

Modify an existing identity activity analysis

To change the identity, provider, or time range for an open analysis, select New Analysis and update the fields. Selecting Analyze Identity Activity re-runs the analysis with the new parameters.

Next Steps

Did this answer your question?