# Microsoft Entra ID Entity Analytics vs Azure

**URL:** <https://discuss.elastic.co/t/microsoft-entra-id-entity-analytics-vs-azure/360498>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [May 29, 2024, 6:18pm UTC](https://discuss.elastic.co/t/microsoft-entra-id-entity-analytics-vs-azure/360498 "2024-05-29T18:18:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 30, 2024, 4:33pm UTC](https://discuss.elastic.co/t/microsoft-entra-id-entity-analytics-vs-azure/360498/2 "2024-05-30T16:33:29Z")

</div>

Hello,

W've been using it and it's awesome for a lot of reasons.

Something you need to be aware of, is the different timestamps. Depending on the dataview you create the data can visualise in total different ways, because it takes the ingest timestamp vs the asset created timestamp vs the asset last signin timestamp.

There is definitely room for improvement. Some examples:

- I was hoping we could use this data to enrich other datasets which only contains the user id and not the user name. But to achieve that, a transform needs to be added and an enrich index. Imho this should have come out of the box.

> [@Get user.name from user.id in Entity Analytics Azure Entra ID dataset](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/4):
>
> I guess it doesnt work on datastreams. Is there a builtin way to schedule it? So that it contains the most recent entra id user info? I'm not exactly sure but I would probably start by looking at making a transform on your data stream to a summarized index and then using that summarized index as the source for your enrich policy

- The host.name field is not lowercase fqdn. So I had to add a custom ingest pipeline which lowercases the host.name and append our domain. That way we can correlate with other datasets which contain lowercase fqdn.

> [@Lowercase host.name FQDN Beta Fleet policy setting](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047):
>
> Hello, We are working through an effort to make sure host.name is indexed as lowercase fqdn everywhere. We put the original hostname in host.hostname. Considering we have multiple domains, this is not only necessary to avoid host collision problems, but it also allows us to correlate host datasets with network datasets. We have 200+ datasets and some of them are logging camelcase, other uppercase, others lowercase, so there is also a requirement to lowercase the host.name everywhere. …

- It only contains Entra ID devices, not Intune data. Hopefully Elastic will release an Intune Entity Analyticvs dataset soon.

- What we kind of need is an easy! way to compare datasets. I'm having a hard time to compare the Entra ID Device dataset with other datasets, so we can detect, for example, which hosts are missing a certain agent.

WillemD

---

_[View the full topic](https://discuss.elastic.co/t/microsoft-entra-id-entity-analytics-vs-azure/360498)._
