From d0076069772c70c9f85db01f253eef980d084499 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 16 Feb 2017 14:40:07 -0800 Subject: [PATCH] update user account topic --- windows/keep-secure/TOC.md | 2 +- ...-entity-windows-defender-advanced-threat-protection.md | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/keep-secure/TOC.md b/windows/keep-secure/TOC.md index 20813ab2fc..9616c84dc1 100644 --- a/windows/keep-secure/TOC.md +++ b/windows/keep-secure/TOC.md @@ -751,7 +751,7 @@ ###### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) ###### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) ##### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md) -##### [Investigate a user entity](investigate-user-entity-windows-defender-advanced-threat-protection.md) +##### [Investigate a user account](investigate-user-entity-windows-defender-advanced-threat-protection.md) ##### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) #### [Take response actions](response-actions-windows-defender-advanced-threat-protection.md) ##### [Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) diff --git a/windows/keep-secure/investigate-user-entity-windows-defender-advanced-threat-protection.md b/windows/keep-secure/investigate-user-entity-windows-defender-advanced-threat-protection.md index d4a84e3c38..f9a614b176 100644 --- a/windows/keep-secure/investigate-user-entity-windows-defender-advanced-threat-protection.md +++ b/windows/keep-secure/investigate-user-entity-windows-defender-advanced-threat-protection.md @@ -1,6 +1,6 @@ --- -title: Investigate user entities in Windows Defender Advanced Threat Protection -description: Use the investigation options to investigate alerts related to a user account. +title: Investigate user account in Windows Defender Advanced Threat Protection +description: Investigate a user account in Windows Defender Advanced Threat Protection for potential compromised credentials or pivot on the associated user account during an investigation. keywords: investigate, account, user, user entity, alert, windows defender atp search.product: eADQiWindows 10XVcnh ms.prod: w10 @@ -10,7 +10,7 @@ ms.pagetype: security author: mjcaparas localizationpriority: high --- -# Investigate a user account associated with a Windows Defender ATP alert +# Investigate a user account in Windows Defender ATP **Applies to:** @@ -23,7 +23,7 @@ localizationpriority: high [Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] ## Investigate user account entities -Identify user accounts with the most active alerts (displayed on dashboard as "Users at risk") and and investigate cases of potential compromised credentials, or pivot on the associated user account when investigating an alert or machine to identify possible lateral movement between machines with that user account. +Identify user accounts with the most active alerts (displayed on dashboard as "Users at risk") and investigate cases of potential compromised credentials, or pivot on the associated user account when investigating an alert or machine to identify possible lateral movement between machines with that user account. You can find user account information in the following views: - Dashboard