Loading...

Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences

Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences

Microsoft has announced upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences. The move is part of the convergence of both Microsoft Defender for Identity and Microsoft Defender for Cloud Apps into Microsoft Defender XDR services. The retirement of Defender for Identity's Active Directory and alerts data from Defender for Cloud Apps dedicated experiences will begin rolling out in late January 2025 and is expected to complete in early March 2025. All affected data and functionality will remain available through Microsoft Defender XDR unified experiences following this change. However, Active Directory activities coming from Defender for Identity will no longer be available in Defender for Cloud Apps activity logs, and Defender for Cloud Apps activity policies will no longer trigger based on Active Directory data. New Active Directory activities, as well as Defender for Identity's alerts data, will no longer be available through Defender for Cloud Apps Activities API, Alerts API, or dedicated SIEM agents. Instead, all activities and alerts data will be available through Defender XDR Streaming API and Event Hubs. The identities page under 'Assets' in the XDR portal will be updated to better support the new experiences. To ensure a smooth transition, users are encouraged to create new custom detections.

Overall, the changes aim to move away from legacy experiences and enhance the unified experiences in Microsoft Defender XDR services.

The post Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences appeared first on M365 Admin.

Published on:

Learn more
M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Defender for Cloud Apps experience in Defender XDR

The Defender for Cloud Apps experience in Defender XDR is now generally available, with auto-redirection enabled by default. Starting June 16t...

1 year ago

Easily detect CVE-2024-21427 with Microsoft Defender for Identity

A recent CVE-2024-21427 Windows Kerberos Security Feature Bypass Vulnerability has been fixed to prevent the potential bypass of authenticatio...

1 year ago

Cloud Discovery anomaly detection policy to be retired

Microsoft has announced that the "Cloud Discovery anomaly detection" policy in Defender for Cloud Apps will be retired due to the high rate of...

1 year ago

Public preview announcement – support all Microsoft Defender for Cloud Apps users by Microsoft Defender XDR portal

Microsoft has announced that all admin roles supported by Microsoft Defender for Cloud Apps will have access to the entire Microsoft Defender ...

1 year ago

Threat Protection report page retirement

Microsoft has announced the retirement of the Threat Protection report page that is accessed through Reports > Endpoints > Threat Protection. ...

1 year ago

Force redirection from Microsoft Defender for Cloud Apps to Microsoft Defender XDR public preview announcement

Microsoft Defender is moving towards the Microsoft Defender XDR portal and as part of this transition, users from customers who have opted int...

1 year ago

Data Loss Prevention – Out-of-box Advanced Hunting queries for Data Loss Prevention incidents in Microsoft 365 Defender

This post provides information about how to use out-of-box advanced hunting queries for Data Loss Prevention incidents in Microsoft 365 Defend...

1 year ago

Improving the pipeline of Identity-related tables in Microsoft 365 Defender Advanced hunting

Microsoft 365 Defender Advanced hunting is making an improvement to the pipeline of Identity-related tables to reduce delay times in identity-...

1 year ago

Configuration Change – Microsoft Defender for Cloud Apps threat protection policies

Microsoft is making changes to the default threat protection policies for Microsoft Defender for Cloud Apps. These policies will now be disabl...

2 years ago

Advanced Threat Hunting with Microsoft 365 Defender

In this podcast episode, Michael and Michael dive into the world of advanced threat hunting using Microsoft 365 Defender. Joining the conversa...

2 years ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy