Fix/Update Microsoft Sentinel Account Entity Naming to avoid inconsistent account identification in incidents and alerts
By December 13, 2025, update Microsoft Sentinel analytic rules, automation, workbooks, and queries to use the new account entity naming precedence: UPN prefix → name → display name. Use coalesce patterns to avoid issues in incidents, alerts, dashboards, and playbooks relying on account names. Test changes before rollout. On December 13, 2025, you may encounter issues if you haven’t updated your analytic rules, automation rules/playbooks, workbooks, hunting queries, or custom integrations to be precedence-aware for account entity naming. We’ve standardized the account entity naming logic in Microsoft Sentinel incidents and alerts, where the account entity naming priority is: UPN prefix → name → display name. Please update your queries and automations to use the new precedence pattern. You are receiving this message because our reporting indicates your organization may be using Microsoft Sentinel incidents, alerts (AlertV3), or related automation. When this will happen: December 13, 2025 How this will affect your organization: If you don’t fix this problem, these queries, automations, dashboards, and reports that reference account names may be affected: Analytics (KQL) that filter by, join on, or normalize account names Automation rules & playbooks (e.g., Logic Apps) that map Account.Name or compare it to other identity fields Workbooks & dashboards that show account name or aggregate by that value Hunting queries that coalesce or parse account identity fields Any users or systems relying on display name as the account identifier What you need to do to prepare: To fix this problem you need to update your KQL queries and automation logic to use the new precedence-aware pattern for account entity naming. Specifically, use a coalesce pattern (e.g., coalesce(Name, DisplayName)) wherever you reference the account name, and validate your workbooks, dashboards, and playbooks against the new logic. Test changes in a nonproduction workspace before rollout. Message ID: MC1183015
The post Fix/Update Microsoft Sentinel Account Entity Naming to avoid inconsistent account identification in incidents and alerts appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Fix/Update Microsoft Sentinel Account Entity Naming to avoid inconsistent account identification in incidents and alerts
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...