# User Incidents in Hexnode UEM | Monitoring Behavioral Security Risks

**Architecture Snapshot:** The **Users** subtab lists identity-centric issues detected within the UEM environment. While Endpoint incidents focus on hardware state, User incidents monitor **behavioral patterns**, authentication discrepancies, and policy violations tied to individual managed accounts to ensure consistent security across the organization.

Logic and Behavioral Detection
------------------------------

User incidents primarily target credential integrity and behavioral compliance. These alerts are generated when Hexnode identifies patterns that suggest user account misuse, potential compromise, or violations of administrative resource limits.

How to access User Incidents?
-----------------------------

To access the User incidents:

1. Login to the Hexnode console.
2. Navigate to the **Incidents** tab.
3. Access the **Users** sub-tab.

User Incident Sources Matrix
----------------------------

 SourceTechnical Logic and Management Impact**Multi-device Users**Triggers when a user is provisioned with **more than three devices**. This prevents resource over-allocation and maintains compliance with per-user licensing or policy limits.**Geofence Violators**Lists users whose assigned devices consistently exit **predefined geofence boundaries**. Frequent violations may indicate unauthorized travel or intentional non-compliance with location-based restrictions.**Location Anomalies**Detects **“impossible travel”** scenarios where devices report locations from distant geographical regions within an improbable timeframe. This flags potential **GPS spoofing** or account hijacking.Strategic Importance of User Tracking
-------------------------------------

By monitoring identity-based incidents, organizations can achieve the following:

- **Early Threat Detection:** Rapidly identify account misuse before a data breach occurs.
- **Authentication Integrity:** Enforce consistent sign-in and geofencing policies across the user base.
- **Governance and Auditing:** Maintain a detailed log of user-driven events for internal and external compliance audits.

**Operational Use Case:** If a user account reports a location in New York at 10:00 AM and a location in London at 11:00 AM, Hexnode triggers a *Location Anomaly* incident. The administrator can instantly freeze the account and investigate potential GPS spoofing or unauthorized credential sharing.