---
title: Entity Risks
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > Cloud SIEM > Triage and Investigate > Entity Risks
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Entity Risks

## Overview{% #overview %}

[Cloud SIEM's Entity Risks](https://app.datadoghq.com/security/siem/entity-risks) consolidates multiple data sources, such as SIEM threats and Cloud Security insights, into a profile representing a single security entity, such as an IAM user.

{% alert level="info" %}
Entity Risks was previously known as Risk Insights.
{% /alert %}

With Entity Risks, you can:

- Explore entities, filtering them by attributes such as entity provider, entity type, entity name, risk score severity, risk score, and configuration risks.
- View all data relevant to an entity, such as signals, misconfigurations, and identity risks.
- Group risks by user identity to see one row per person, with their total risk across every account they act through.
- Configure notifications so you can address risky entities, or risky people, as they emerge.
- Triage relevant items in bulk.
- Take mitigation steps such as creating a global suppression or creating a case for an entity.

## Prerequisites{% #prerequisites %}

- To use Entity Risks, configure at least one of the following supported log sources to send logs to Cloud SIEM, with an active Open Cybersecurity Schema Framework (OCSF) pipeline:
  - **Sources that provide identity and resource entities** (such as users, service identities, assumed roles, compute instances, and storage containers): AWS, Azure, GCP, GitHub, Microsoft 365, and Okta.
  - **Sources that provide user entities identified by email address**: 1Password, Cisco Duo, Cloudflare, CrowdStrike, Google Workspace, JumpCloud, LastPass, Salesforce, Slack, and Zscaler Internet Access (ZIA).
- Many supported sources use an [out-of-the-box OCSF pipeline](https://docs.datadoghq.com/security/cloud_siem/ingest_and_enrich/open_cybersecurity_schema_framework.md#supported-out-of-the-box-ocsf-pipelines) that requires no additional configuration. If a supported source is not producing entities, confirm that its out-of-the-box OCSF pipeline is active. Pipelines that predate OCSF support, and customized pipelines, may not include the required OCSF processing.
- Datadog recommends configuring an [Entity Pack](https://docs.datadoghq.com/security/cloud_siem/ingest_and_enrich/entity_packs.md) for your identity provider (Okta, Google Workspace, or Microsoft Entra ID) on the [Content Packs](https://docs.datadoghq.com/security/cloud_siem/ingest_and_enrich/content_packs.md) page. When user identities sync, Entity Risks resolves each person's accounts into a single user identity and rolls up their risk. User identity notifications also become available. Without an Entity Pack, entities are only ever scored and alerted on individually. See Risk grouped by user identity.
- (Optional) To view associated Cloud Security insights in the entity panel, [Cloud Security must be configured](https://docs.datadoghq.com/security/cloud_security_management/setup.md).

## Explore Entity Risks{% #explore-entity-risks %}

### Query and filter entities{% #query-and-filter-entities %}

On the [Entity Risks](https://app.datadoghq.com/security/siem/entity-risks) page, you can view all entities that have a non-zero risk score associated to them.

{% image
   source="https://docs.dd-static.net/images/security/entities/entities-explorer4.5a80601936a93bcac3185e69dc8c62e6.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/entities/entities-explorer4.5a80601936a93bcac3185e69dc8c62e6.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Entity Risks page listing risks and their scores, with one user identity row expanded to show the entities beneath it" /%}

### Risk grouped by user identity{% #risk-grouped-by-user-identity %}

In a federated environment, one person typically acts through many separate entities, such as several email aliases, an IAM user, assumed roles, and a code repository account. Viewed individually, none of these entities shows that person's total risk.

When you configure an [Entity Pack](https://docs.datadoghq.com/security/cloud_siem/ingest_and_enrich/entity_packs.md) for your identity provider, Cloud SIEM syncs user identities from that provider. It then resolves the entities that belong to each one. Entities that resolve to one person are grouped under a single user identity row, named for that person. That row's risk score is the sum of the risk scores of the entities beneath it. Grouping is applied automatically whenever an identity provider is connected.

To investigate a user identity:

1. In [Entity Risks](https://app.datadoghq.com/security/siem/entity-risks), find a row with an expand arrow and a count of associated entities.
1. Click the arrow to expand the row and see each entity resolved to that user identity, along with its own risk score, type, source, and signal count.
1. Click an entity to open its side panel and continue investigating, as described in Quickly build context on an entity.

{% alert level="info" %}
Entity Risks only groups entities that resolve unambiguously to a user identity. Entities that cannot resolve to a single identity continue to appear as individual rows, so the same person may still appear more than once.
{% /alert %}

### Quickly build context on an entity{% #quickly-build-context-on-an-entity %}

Click an entity in [Entity Risks](https://app.datadoghq.com/security/siem/entity-risks) to open the entity side panel.

{% image
   source="https://docs.dd-static.net/images/security/entities/entity-side-panel4.ad28c886ab6b3f48be7098cfdedabd0d.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/entities/entity-side-panel4.ad28c886ab6b3f48be7098cfdedabd0d.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The side panel for an entity, showing the What Happened summary and the Risk Contributors list" /%}

The What Happened section of the panel summarizes the count of signals, misconfigurations, and identity risks and how they have contributed to the risk score, as well as any potential configuration risks.

The Risk Contributors section displays the list of fired signals, relevant misconfigurations, and identity risks.

The What Happened and Risk Contributors sections include only the signals, misconfigurations, and identity risks that contribute points to the entity's risk score. To see all signals associated with the entity, including those that do not affect the score, click View All Related Signals; for misconfigurations and identity risks, click View in Vulnerability Explorer.

### Triage and mitigate threats in bulk{% #triage-and-mitigate-threats-in-bulk %}

The Risk Contributors section of the entity side panel includes the available mitigation steps. Select the items you want to act on, then use the inline actions to set a triage state, assign an item, create a security case, declare an incident, or create a suppression.

## Configure notifications for Entity Risks{% #configure-notifications-for-entity-risks %}

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com



{% alert level="danger" %}
Notification rules are not supported for the {% placeholder "user-datadog-site-name" /%} site.
{% /alert %}


{% /callout %}

You can configure Datadog to send you notifications as soon as it detects new threats that match your criteria.

1. Navigate to the Create a new Entity Risk notification page. There are two ways to do this:
   - In Datadog, go to the [Entity Risks](https://app.datadoghq.com/security/siem/entity-risks) page, then click Create Notification Rule.
   - In Datadog, go to Cloud SIEM > Settings. Under Products, in the Cloud SIEM section, click [Entity Risks](https://app.datadoghq.com/security/configuration/siem/entity-risks); then, under Notification rules, click New notification rule.
1. Under Group risk by, choose what the rule measures:
   - Individual entity: The rule evaluates each entity's own risk score.
   - User identity: The rule evaluates a user identity's rolled-up risk score, which sums the scores of every entity resolved to that person. This option is available after you configure an Entity Pack and user identities are syncing. See Notify on rolled-up user identity risk.
Important alert (level: warning): You cannot change a rule's grouping after you create the rule. To use a different grouping, create another rule.
1. Under Define entity attributes, specify the attributes that should trigger notifications when Datadog detects them on an entity. Beside Entities matching, start typing entity attributes and values. As you type, the preview table dynamically displays the entities that match your criteria.Important alert (level: info): This step is optional, but if you don't enter any attributes, the notification defaults to sending alerts for all entities.
1. Under Set notification conditions, set the trigger condition based on entity severity or risk score value:
   - Entity severity: Triggers a notification when an entity reaches a certain severity level. Select an operator, then select a severity level. For the risk score that corresponds to each severity level, see Entity severity thresholds.
   - Risk score value: Triggers a notification when the entity's risk score crosses a specified threshold. Specify the threshold for notifications.
1. Under Configure notification, enter a name for the notification, add a custom message body, and specify recipients to send it to.
   - Optionally, you can also turn on re-notifications, and specify the period of time that should pass before Datadog re-notifies the recipients that the entity still meets the criteria you specified.
1. To verify your setup, click Test Notification to send a test notification to the configured recipients.
1. Click Save Notification.

### Notify on rolled-up user identity risk{% #notify-on-rolled-up-user-identity-risk %}

A rule grouped by User identity notifies you when one person's total risk across all of their entities crosses a threshold. This helps you identify risk that is spread across several entities, where no single entity crosses your individual entity threshold.

Rules grouped by user identity differ from individual entity rules in the following ways:

- **Matching attributes are user attributes.** Instead of entity attributes, you query the attributes of the resolved user identity, consistent with what you see in User Inventory. For example, you can query by identity provider, user type, department, job title, or office location. The preview table shows the matching user identities and their rolled-up risk scores.
- **Conditions evaluate the rolled-up score.** As with individual entity rules, you can trigger on either an entity severity level or a risk score value, and the same entity severity thresholds apply. In both cases, the condition is evaluated against the user identity's rolled-up risk score rather than any single entity's score.
- **Notifications fire on threshold crossing.** Datadog notifies you when a user identity enters the above-threshold state, not on every evaluation while it remains above it. If a user identity is already above the threshold when you create the rule, Datadog sends one notification. Use re-notifications to be reminded while the user identity stays above the threshold.
- **Message content is person-centric.** Template variables include the user identity's display name, identity provider, rolled-up risk score, the number of contributing entities, and the top contributing entities with their scores.
- **The notification links to User Inventory.** The notification's primary link opens the user identity's side panel in User Inventory.

Rules grouped by user identity and rules grouped by individual entity coexist, and the rules list labels each rule with its grouping. Both kinds of rule count toward the same limit of 100 notification rules per organization.

## Risk scoring{% #risk-scoring %}

An entity's risk score approximates the entity's risk level over the past 14 days of activity. Datadog calculates the risk score from the characteristics of the entity's associated signals, such as the severity level of the signal, and how many times the signal has fired.

### View and customize signal score impacts{% #view-and-customize-signal-score-impacts %}

Each signal has a score impact based on its severity. Datadog assigns a default number of points to each signal severity. To view or override the default score impacts for your organization, as well as impacts for misconfigurations and identity risks, go to the [Entity Risks settings page](https://app.datadoghq.com/security/configuration/siem/entity-risks).

If you change the score impacts, Datadog immediately and retroactively applies them to all existing entity risk scores. You can use the updated scores to assess the impact of your changes on your Entity Risks notifications moving forward, so you can reduce the noise and increase the signal they provide.

{% alert level="info" %}
A signal's score impact lasts for 14 days, after which the score drops to `0`.
{% /alert %}

| Signal Severity  | Number of points |
| ---------------- | ---------------- |
| `Critical`       | `100`            |
| `High`           | `50`             |
| `Medium`         | `5`              |
| `Low` and `Info` | `0`              |

### Entity severity thresholds{% #entity-severity-thresholds %}

The severity threshold of an entity is calculated by adding up the score impact for all signals associated with the entity. The same thresholds apply to a user identity: its severity is derived from its rolled-up risk score, which is the sum of the risk scores of every entity resolved to it.

| Severity Threshold | Risk score                                         |
| ------------------ | -------------------------------------------------- |
| `Critical`         | Greater than or equal to `100`.                    |
| `High`             | Greater than or equal to `50` and less than `100`. |
| `Medium`           | Greater than or equal to `25` and less than `50`.  |
| `Low`              | Greater than or equal to `10` and less than `25`.  |
| `Info`             | Less than `10`.                                    |

## Further reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Sync user identities into Cloud SIEM with Entity Packs](https://docs.datadoghq.com/security/cloud_siem/ingest_and_enrich/entity_packs.md)
- [Accelerate investigations with Datadog Cloud SIEM Risk-based Insights and AWS Entity Analytics](https://www.datadoghq.com/blog/risk-prioritization-entity-analytics/)
- [AI in cloud security investigations: The role of UEBA and better telemetry](https://www.datadoghq.com/blog/ai-powered-threat-analysis)
- [What's new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations](https://www.datadoghq.com/blog/cloud-siem-whats-new-rsa-2026)
