Microsoft Defender XDR: Unified identity timeline on the Identity page
Microsoft Defender XDR is enhancing the Identity page’s Timeline tab to provide a unified, chronological view of identity-related activities and alerts from multiple Microsoft security sources. Rolling out mid-September to mid-October 2026, it offers improved context, filtering, and automatic updates without changing existing policies. No action is required to enable it. What and Why: We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience. The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks. Rollout schedule: Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026. Impact on your organization: This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal. After rollout: The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts. Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available. New filtering and investigation fields will be available, including: Source table Session ID Unique token identifier Conditional Access Target Additional information Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources. The timeline will automatically refresh when linked accounts change. This update does not modify existing security policies, user accounts, permissions, or configurations. Action required / Recommendations: No action is required to enable the core timeline experience. To help your organization take advantage of this enhancement, we recommend that you: Inform SOC and incident response teams about the updated Timeline experience. Review investigation runbooks that require analysts to pivot […]
The post Microsoft Defender XDR: Unified identity timeline on the Identity page appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender XDR: Unified identity timeline on the Identity page
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Intune: Windows Health Attestation Migration to Microsoft Azure Attestation
Microsoft Intune will migrate Windows Health Attestation compliance evaluation from the current Device Health Attestation (DHA) service to Mic...
Dynamics 365 Commerce – Print receipts using Adyen payment terminal printers
We are announcing the ability to print receipts using the built-in printer on supported Adyen payment terminals in Dynamics 365 Commerce. This...
Outlook: Multi Account Search
Users will be able to see results from multiple mailboxes interweaved in a single ranked list and will be able to do standard mail actions. Pr...
Dynamics 365 Field Service: Manage rental service demand with work order requests
Rental organizations need to coordinate commercial rental activity, equipment availability, asset condition, and service execution across mult...
Microsoft Teams: Schedule Channel Meetings from Outlook Calendar
Users will be able to schedule Microsoft Teams channel meetings directly from Outlook Calendar. This streamlines meeting creation and helps ke...
Microsoft 365 admin center: Optional Public CDN Support in Brand Center Setup
We are updating the Brand Center setup experience so that administrators can set up Brand Center without enabling Public CDN. Today, Public CD...
Dynamics 365 Field Service: Book Work Orders with Multiple Requirements
Dispatchers can now select which resource requirement to schedule when booking a work order that has multiple requirements. The new Book exper...
Brand Skill support now available in PPT Copilot [Web]
Brand managers can upload custom presentation skills as Markdown files to Brand Kit for use with Copilot in PowerPoint Web, enabling consisten...
Brand Skill support now available in PPT Copilot [Desktop]
Brand managers can now upload custom presentation skills as Markdown files to Brand Kit for use with Copilot in PowerPoint Desktop, enabling c...