Loading...

Microsoft Defender XDR: Unified identity timeline on the Identity page

Microsoft Defender XDR: Unified identity timeline on the Identity page

Microsoft Defender XDR is enhancing the Identity page’s Timeline tab to provide a unified, chronological view of identity-related activities and alerts from multiple Microsoft security sources. Rolling out mid-September to mid-October 2026, it offers improved context, filtering, and automatic updates without changing existing policies. No action is required to enable it. What and Why: We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience. The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks. Rollout schedule: Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026. Impact on your organization: This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal. After rollout: The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts. Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available. New filtering and investigation fields will be available, including: Source table Session ID Unique token identifier Conditional Access Target Additional information Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources. The timeline will automatically refresh when linked accounts change. This update does not modify existing security policies, user accounts, permissions, or configurations. Action required / Recommendations: No action is required to enable the core timeline experience. To help your organization take advantage of this enhancement, we recommend that you: Inform SOC and incident response teams about the updated Timeline experience. Review investigation runbooks that require analysts to pivot […]

The post Microsoft Defender XDR: Unified identity timeline on the Identity page appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender XDR: Unified identity timeline on the Identity page

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams

Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...

2 days ago

Microsoft Teams: Enable agents for existing applications in your organization

For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...

2 days ago

Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile

The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...

3 days ago

Planner: Conditional Coloring

Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...

3 days ago

Outlook: Offline settings “Days of email to save” admin policy

Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...

3 days ago

Microsoft Copilot Studio: Agent Sharing amongst makers

Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...

3 days ago

OneDrive Photos on Windows: admin controls and policy support

OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...

3 days ago

Admin app retiring in Teams, Outlook and Microsoft365.com

The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...

3 days ago

Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting

Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...

3 days ago

Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices

The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...

3 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.