Microsoft Defender XDR: Unified identity timeline on the Identity page
Microsoft Defender XDR is enhancing the Identity page’s Timeline tab to provide a unified, chronological view of identity-related activities and alerts from multiple Microsoft security sources. Rolling out mid-September to mid-October 2026, it offers improved context, filtering, and automatic updates without changing existing policies. No action is required to enable it. What and Why: We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience. The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks. Rollout schedule: Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026. Impact on your organization: This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal. After rollout: The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts. Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available. New filtering and investigation fields will be available, including: Source table Session ID Unique token identifier Conditional Access Target Additional information Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources. The timeline will automatically refresh when linked accounts change. This update does not modify existing security policies, user accounts, permissions, or configurations. Action required / Recommendations: No action is required to enable the core timeline experience. To help your organization take advantage of this enhancement, we recommend that you: Inform SOC and incident response teams about the updated Timeline experience. Review investigation runbooks that require analysts to pivot […]
The post Microsoft Defender XDR: Unified identity timeline on the Identity page appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender XDR: Unified identity timeline on the Identity page
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...