---
title: BeyondTrust Identity Security Insights suspicious identity activity detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  suspicious identity activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights suspicious identity activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect suspicious identity-related activity that may indicate misuse, misconfiguration, or potential compromise of identities within the environment.

## Strategy{% #strategy %}

Monitor identity events to identify behaviors that deviate from expected operational processes. This detection focuses on surfacing identity activities that may introduce security gaps.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the suspicious activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the activity aligns with approved identity management processes, user intent, and organizational policies.
1. If the activity is unauthorized, take appropriate remediation actions in accordance with incident response.
