Microsoft Advanced Threat Analytics(ATA) is part of EMS, it helps companies identify the suspicious
user and device activity. By leveraging advanced machine-learning technology, ATA helps identify suspicious user and device activity while providing clear and relevant attack information.
ATA analyzes all on-premises Active Directory network traffic. After analysis,
ATA builds an Organizational Security Graph, a living, continuously updated the view of all users, devices, and resources within an organization that understands normal network behavior. ATA looks for any abnormalities in the entities’ behavior and raises alerts.