KQL - User Device & Agents Profiler
Aggregates identity, endpoint, cloud application, and messaging telemetry to build a consolidated profile of the devices, clients, applications, and user agents associated with a specific user account. The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment. This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
Microsoft Sentinel (KQL)

