Microsoft Defender XDR: Unified response actions across identity accounts
Microsoft Defender XDR unifies identity response actions across linked accounts, enabling security teams to manage actions like disabling accounts or forcing password changes from one workflow. It supports multiple identity systems and SaaS apps, enhancing response speed and consistency. Rollout begins mid-October 2026 worldwide. What and why: Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts. Security teams will be able to apply supported response actions to all supported accounts associated with an identity, or to selected accounts, from a single workflow. Available actions depend on the identity system or connector managing the account and may include: Disable account Enable account Revoke session Mark as compromised Force password change Supported identity systems and applications include: Active Directory Microsoft Entra ID Okta CyberArk Identity SailPoint Identity Security Cloud Google Workspace Salesforce Box This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications. Rollout schedule: Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026. Who is affected Security Operations Center (SOC) analysts Incident responders Identity administrators Administrators managing Microsoft Defender-connected identity systems Platforms and services Microsoft Defender XDR Microsoft Defender for Identity Microsoft Defender for Cloud Apps Microsoft Entra ID Supported third-party identity provider and SaaS application connectors What will happen Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center. Available response actions vary based on the identity system or connector managing each account. Administrators can review action status in Action center and in audit records generated by the target system. No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action. Action required / Recommendations: No action is required to enable this capability. However, we recommend that administrators: Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles. Verify Microsoft Defender for Identity action account configuration for Active Directory response actions. If using Microsoft Defender for Identity sensor version […]
The post Microsoft Defender XDR: Unified response actions across identity accounts appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender XDR: Unified response actions across identity accounts
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...