---
title: >-
  BeyondTrust Identity Security Insights abnormal administrator activity
  detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  abnormal administrator activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights abnormal administrator activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect potentially abnormal or high-risk administrative activity.

## Strategy{% #strategy %}

Monitor administrative activity across identity systems and managed assets to identify actions that deviate from expected usage patterns.

## Triage and Response{% #triage-and-response %}

1. Identify the administrator account `{{@entityName}}` associated with the detected activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Evaluate whether the activity aligns with approved administrative responsibilities and organizational security policies.
1. If the activity is unauthorized, take appropriate action in accordance with established incident response.
