Investigate
EDR, Email, SaaS, Identity, and Cloud
Five domain workbenches over one custody path. Each requires the matching domains:*:read permission. Live mutations require a source-native executor plus approval scopes — a button is a request path, not a vendor guarantee by itself.
Shared design across domains
These pages specialize tooling for the domain an analyst is working in — device inventory versus message explorer versus OAuth grant review — without creating five independent SIEM products. Each can show a source custody panel describing which telemetry families and detection rules apply. Each queues response requests into the same response_actions system used by Incidents.
Navigation is permission-gated. Without domains:edr:read you should not see EDR; the same pattern applies to email, saas, identity, and cloud. Middleware also enforces these gates server-side for the corresponding routes.
Domain map
| Route | Permission | Primary tabs / tools | Example requests |
|---|---|---|---|
| /edr | domains:edr:read | Devices, Detections, Vulnerabilities, Response sessions, Software, Exclusions, Sensor policies | Isolate endpoint, quarantine file |
| domains:email:read | Message explorer, Campaigns, Quarantine, Submissions, Allow/block, Mail-flow, Protection policies | Quarantine message, create ticket | |
| /saas | domains:saas:read | Apps, OAuth grants, Sessions, Sensitive files, Activity, Policies, Governance log | Revoke session/grant, suspend user |
| /identity | domains:identity:read | Risks, Sign-ins, Privileged access, Workloads, Auth methods, Access reviews, Access policies | Disable account, revoke session, reset MFA |
| /cloud | domains:cloud:read | Resources, Findings, Attack paths, Permissions, Data exposure, Compliance, Workflow automation | Block egress, rotate credential, quarantine workload |
How to work a domain case
Start from an incident when one exists, then open the domain workbench that owns the evidence family you need. Use the custody panel to confirm which telemetry is actually present. Request containment only when the evidence supports it, then approve under the correct scope. If the domain page shows “not reported” fields, that means connectors have not populated them — not that the asset is clean.
Some header actions (for example certain “start hunt” toasts) remain UI affordances until a live executor is wired. Conditional access or policy toggles in evaluation can be local UI state. Treat live mutation as request + approval + executor.
Maturity notes operators should know
Microsoft Sentinel is the first fully in-console credentialed connector path. Several Defender family and third-party kinds are guide-first today (see Integrations). Domain pages can still teach workflow and queue response requests, but full live executor coverage varies by action type and connector maturity. Prefer honesty over theatre when a control is scaffold.