Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences

Microsoft has announced upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences. The move is part of the convergence of both Microsoft Defender for Identity and Microsoft Defender for Cloud Apps into Microsoft Defender XDR services. The retirement of Defender for Identity's Active Directory and alerts data from Defender for Cloud Apps dedicated experiences will begin rolling out in late January 2025 and is expected to complete in early March 2025. All affected data and functionality will remain available through Microsoft Defender XDR unified experiences following this change. However, Active Directory activities coming from Defender for Identity will no longer be available in Defender for Cloud Apps activity logs, and Defender for Cloud Apps activity policies will no longer trigger based on Active Directory data. New Active Directory activities, as well as Defender for Identity's alerts data, will no longer be available through Defender for Cloud Apps Activities API, Alerts API, or dedicated SIEM agents. Instead, all activities and alerts data will be available through Defender XDR Streaming API and Event Hubs. The identities page under 'Assets' in the XDR portal will be updated to better support the new experiences. To ensure a smooth transition, users are encouraged to create new custom detections.
Overall, the changes aim to move away from legacy experiences and enhance the unified experiences in Microsoft Defender XDR services.
The post Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences appeared first on M365 Admin.
Published on:
Learn moreRelated posts
Microsoft Defender for Cloud Apps experience in Defender XDR
The Defender for Cloud Apps experience in Defender XDR is now generally available, with auto-redirection enabled by default. Starting June 16t...
Easily detect CVE-2024-21427 with Microsoft Defender for Identity
A recent CVE-2024-21427 Windows Kerberos Security Feature Bypass Vulnerability has been fixed to prevent the potential bypass of authenticatio...
Cloud Discovery anomaly detection policy to be retired
Microsoft has announced that the "Cloud Discovery anomaly detection" policy in Defender for Cloud Apps will be retired due to the high rate of...
Public preview announcement – support all Microsoft Defender for Cloud Apps users by Microsoft Defender XDR portal
Microsoft has announced that all admin roles supported by Microsoft Defender for Cloud Apps will have access to the entire Microsoft Defender ...
Threat Protection report page retirement
Microsoft has announced the retirement of the Threat Protection report page that is accessed through Reports > Endpoints > Threat Protection. ...
Force redirection from Microsoft Defender for Cloud Apps to Microsoft Defender XDR public preview announcement
Microsoft Defender is moving towards the Microsoft Defender XDR portal and as part of this transition, users from customers who have opted int...
Data Loss Prevention – Out-of-box Advanced Hunting queries for Data Loss Prevention incidents in Microsoft 365 Defender
This post provides information about how to use out-of-box advanced hunting queries for Data Loss Prevention incidents in Microsoft 365 Defend...
Improving the pipeline of Identity-related tables in Microsoft 365 Defender Advanced hunting
Microsoft 365 Defender Advanced hunting is making an improvement to the pipeline of Identity-related tables to reduce delay times in identity-...
Configuration Change – Microsoft Defender for Cloud Apps threat protection policies
Microsoft is making changes to the default threat protection policies for Microsoft Defender for Cloud Apps. These policies will now be disabl...
Advanced Threat Hunting with Microsoft 365 Defender
In this podcast episode, Michael and Michael dive into the world of advanced threat hunting using Microsoft 365 Defender. Joining the conversa...