user-investigation

Analyzes Microsoft Entra ID user accounts for security risks and anomalies.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/msandbu/sentinelday --skill user-investigation-msandbu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: user-investigation
Source: https://github.com/msandbu/sentinelday/tree/main/.github/skills/user-investigation
Command: npx skills add https://github.com/msandbu/sentinelday --skill user-investigation-msandbu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive security investigation for user accounts, identifying suspicious activity, compliance issues, and potential compromises within Microsoft Entra ID.

Core Features & Use Cases

  • Comprehensive Analysis: Analyzes sign-in anomalies, MFA status, device compliance, audit logs, security incidents, and Identity Protection risks.
  • Flexible Output: Delivers results as inline chat summaries, markdown file reports, or polished HTML reports.
  • Use Case: When a security alert flags a user for suspicious sign-ins, this Skill can be invoked to perform a deep dive into their recent activity, pinpointing the exact nature and scope of the threat.

Quick Start

Investigate the user account '[email protected]' for the last 7 days and provide an inline chat summary.

Frequently Asked Questions about user-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a Microsoft Entra ID user account for suspicious sign-in activity?

You can investigate suspicious sign-in activity by analyzing Entra ID audit logs, sign-in anomalies, MFA status, and Identity Protection risk signals. This requires the User Object ID and SID to perform a deep dive into recent activities and identify the scope of the threat.

What is needed to perform a deep dive security analysis on an Office 365 user?

A deep dive security analysis on an Office 365 user requires the User Object ID and SID. These identifiers enable the comprehensive review of audit logs, Office 365 activity, device compliance, and Identity Protection risk signals to identify compromises.

How do I generate an HTML report for an Entra ID identity protection incident response?

To generate an HTML report for an identity protection incident response, analyze Entra ID sign-in patterns, audit logs, and security incidents. The investigation can deliver results directly as a polished HTML report, inline chat summary, or markdown file.

Can I check MFA status and device compliance during a Microsoft Entra ID user investigation?

Yes, a Microsoft Entra ID user investigation comprehensively checks MFA status and device compliance. The analysis evaluates MFA configuration, device compliance states, sign-in anomalies, and audit logs to identify suspicious activity and compliance issues.

What is the best way to summarize Entra ID security alerts for a compromised user?

The best way to summarize Entra ID security alerts is to analyze audit logs, sign-in anomalies, and Identity Protection risks. The investigation delivers a concise inline chat summary detailing the exact nature and scope of the threat for the compromised user.