User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel correlates secur ity events with identity data to build behavioral baselines. UEBA enriches security signals with identity context from Azure AD, Defender for Identity, and other connected identity sources. The IdentityInfo table in Log Analytics stores user account metadata and enrichment information , such as department, group membership, job title, and account status. This table is used to correlate events from the SecurityEvent table and others to link activity to known users and entities. Microsoft documentation s tates: "The IdentityInfo table contains enriched identity information from connected identity providers. It is used by UEBA to correlate with the SecurityEvent table and other identity-related logs."