After an analysis runs, the Identity Activity Details page shows a summary of the investigation scope and a timeline of all identity activity in the selected window.
Scope bar
The bar at the top of the results page shows the parameters of the current analysis:
Field | Description |
Selected Identity | The identity that was analyzed. |
Identity Type | User or Service Principal. |
Source | The identity provider (Entra ID, Microsoft Active Directory, or Okta) |
Start Date | Start date and time of the investigation window. |
End Date | End date and time of the investigation window. |
Click New Analysis to change the identity, provider, or time range and re-run the analysis.
Click Analysis History to view or reopen any previously created analyses.
Activity summary
Below the scope bar, the Identity Activity Details section shows event counts grouped by MITRE TTPs. Select any tile to filter the activity timeline to that tactic only.
Tile | Description |
Total Events | All events recorded for this identity in the investigation window. |
Changed Objects | Objects that were created, modified, or deleted. |
Persistence | Events related to techniques attackers use to maintain access to the environment. |
Privilege Escalation | Events related to techniques attackers use to gain higher privileges or permissions. |
Defense Evasion | Events related to techniques attackers use to avoid detection or bypass security controls. |
Credential Access | Events related to techniques attackers use to steal or obtain credentials such as passwords, tokens, or keys. |
Impact | Events related to techniques attackers use to damage, disrupt, or affect systems and data. |
Activity timeline-graph view
The default view is the activity graph. It shows identity objects as nodes and actions as labeled edges, arranged on a horizontal time axis.
Row labels on the left identify the object type: Users, Groups, Administrative Roles, Service Accounts, Service Principals, Enterprise Applications, Authentication Methods, Devices.
Edge labels show the action type: Create, Modified, or Delete.
Events at the same timestamp in the same object-type row are grouped vertically to reduce clutter.
Each event is color-coded by severity.
Use the forward and backward arrows next to the date range to scroll the timeline horizontally.
Activity timeline-list view
Select the table icon to switch to the list view. Each event appears as a row:
Column | Description |
Time | Timestamp when the event occurred. |
Actor Identity | The identity that performed the action. |
Activity | The specific action (for example, Add user, Update group, Add eligible member to role). |
Target Identity | The identity or object that was affected. |
Action | Create, Modified, or Delete (color-coded pill) |
MITRE TTPs | The mapped MITRE ATT&CK technique and tactic (for example, T1098.003 – Privilege Escalation) |
The count above the table shows how many activities are displayed out of the total.
You can filter the list by Activity Type, Severity, MITRE TTPs , and Target Identity Type.
Export identity activity analysis data
Analysis header: Selected Identity, Identity Type, Source, Start Time, End Time
One row per event: Time, Actor Identity, Actor Identity Type, Activity, Target Identity, Target Identity Type, Action, MITRE TTP, Action Severity.
Next step
When you have identified the scope of the compromise, click View Cyber Recovery Plan to begin recovery. See Build a guided recovery plan.



