Principals
Review synchronized user, group, and workload identity context.
Risk and identity
Connect security signals, identities, permissions, activity, and ownership for review.
Move from isolated findings to a bounded investigation while keeping Microsoft security and identity systems as the authoritative sources.

Lineage provides operational context for risk and identity review. It is not a substitute for Defender, Entra, a SIEM, a CNAPP, or a formal compliance assessment, and it does not certify an environment.
Threat Intelligence
Implemented capabilityThreat Intelligence organizes available risk signals around resources and review scope. Operators can assess what is affected, what related evidence exists, and who should validate the next step.

Access review
Implemented capabilityIdentity views bring available users, groups, service principals, role assignments, and related signals into the review workspace. Effective access can be complex, so operators should validate conclusions against Entra and Azure RBAC.

Review synchronized user, group, and workload identity context.
Inspect available role and scope information.
Compare identity context with recorded operations where available.
Who or what acted
Implemented capabilityActivity Feed helps reviewers inspect operations, outcomes, and available actor context. It can support an investigation, but missing or expired source telemetry cannot be reconstructed by the product.

Advisor evidence
Implemented capabilityAdvisor and related findings can be reviewed with resource, cost, and ownership context. This helps teams decide what warrants validation first rather than treating every recommendation as an automatic action.

Review the recommendation and its source category.
Check affected resources, history, cost, and ownership.
Assign, defer, accept, or document follow-up through the operating workflow.
Controlled follow-up
Implemented capabilityAction Center supports ownership, priority, status, and notes for validated findings. Where a write-class path is configured, separate identity, permission, policy, approval, execution, and audit controls apply.
Route validated follow-up to a named owner.
Record priority, status, and the decision rationale.
Keep approved execution separate from analysis.
Service and advisory
Service and advisorySwaves can help scope evidence, facilitate review, and document remediation ownership. Penetration testing, formal compliance assessment, incident response authority, and managed detection are separate services and are not implied by this product page.
Evaluate Lineage
Bring the affected scope and authoritative source signals; use Lineage to test whether context and ownership improve the outcome.