Investigate

EDR, Email, SaaS, Identity, and Cloud

Five domain workbenches over one custody path. Each requires the matching domains:*:read permission. Live mutations require a source-native executor plus approval scopes — a button is a request path, not a vendor guarantee by itself.

Shared design across domains

These pages specialize tooling for the domain an analyst is working in — device inventory versus message explorer versus OAuth grant review — without creating five independent SIEM products. Each can show a source custody panel describing which telemetry families and detection rules apply. Each queues response requests into the same response_actions system used by Incidents.

Navigation is permission-gated. Without domains:edr:read you should not see EDR; the same pattern applies to email, saas, identity, and cloud. Middleware also enforces these gates server-side for the corresponding routes.

Domain map

RoutePermissionPrimary tabs / toolsExample requests
/edr domains:edr:read Devices, Detections, Vulnerabilities, Response sessions, Software, Exclusions, Sensor policies Isolate endpoint, quarantine file
/email domains:email:read Message explorer, Campaigns, Quarantine, Submissions, Allow/block, Mail-flow, Protection policies Quarantine message, create ticket
/saas domains:saas:read Apps, OAuth grants, Sessions, Sensitive files, Activity, Policies, Governance log Revoke session/grant, suspend user
/identity domains:identity:read Risks, Sign-ins, Privileged access, Workloads, Auth methods, Access reviews, Access policies Disable account, revoke session, reset MFA
/cloud domains:cloud:read Resources, Findings, Attack paths, Permissions, Data exposure, Compliance, Workflow automation Block egress, rotate credential, quarantine workload

How to work a domain case

Start from an incident when one exists, then open the domain workbench that owns the evidence family you need. Use the custody panel to confirm which telemetry is actually present. Request containment only when the evidence supports it, then approve under the correct scope. If the domain page shows “not reported” fields, that means connectors have not populated them — not that the asset is clean.

Some header actions (for example certain “start hunt” toasts) remain UI affordances until a live executor is wired. Conditional access or policy toggles in evaluation can be local UI state. Treat live mutation as request + approval + executor.

Maturity notes operators should know

Microsoft Sentinel is the first fully in-console credentialed connector path. Several Defender family and third-party kinds are guide-first today (see Integrations). Domain pages can still teach workflow and queue response requests, but full live executor coverage varies by action type and connector maturity. Prefer honesty over theatre when a control is scaffold.

Privacy controls

Your visit should be as controlled as your telemetry.

We use necessary cookies to keep the site working. Optional analytics help us understand which product pages are useful. Marketing cookies stay off unless you allow them.