Like the insider systems from Microsoft and Forcepoint/Everfox, the Sentinel cybersecurity system can calculate risk scores for employees, single out those who are assessed as suspicious, detect 'anomalous' behavior, and put employees on 'watchlists'.
Organizations can then investigate their activity in detail to understand whether a suspicious user is an "engineer who often performs unusual activities as part of their job" or a "disgruntled employee who just got passed over for a promotion".
Organizations can use Microsoft Sentinel also to perform 'dragnet' searches for certain behaviors across log data sources according to various criteria in real time.
Via the query language KQL, they can search, for example, for employees who access certain resources or use 'noisy language' in emails.
Almost any functionality in Sentinel, including pre-built detections and reports, is based on KQL. Employers can search up to seven years of log data and 'bring' their 'own' ML models to Sentinel.