SHD / MC Checker

[serviceRestored] DZ1421829 | Microsoft Defender XDR | Admins may see delays to threat intelligence reports in the Security Operation Center (SOC)



DZ1421829 | Microsoft Defender XDR | Admins may see delays to threat intelligence reports in the Security Operation Center (SOC)

Status serviceRestored
Classification advisory
User Impact Admins may have seen delays to threat intelligence reports in the SOC.
Last Updated 07/10/2026 05:09:23
Start Time 07/09/2026 12:00:00
End Time 07/10/2026 01:30:00
Latest Message Title: Admins may see delays to threat intelligence reports in the Security Operation Center (SOC)

User impact: Admins may have seen delays to threat intelligence reports in the SOC.

More info: Users’ threat intelligence reports may have had delays of three to five hours.

Final status: We’ve addressed the aforementioned backend issue and confirmed after monitoring that the backlog of affected data has completed processing.

Scope of impact: This event impacted admins in North America and Europe, who may have seen delays to threat intelligence reports in the SOC.

Start time: Thursday, July 9, 2026, at 12:00 PM UTC

End time: Friday, July 10, 2026, at 1:30 AM UTC

Root cause: A portion of the infrastructure utilized in this function was performing below optimal thresholds and resulted in impact.

Next steps:
– We’re analyzing the affected portion of infrastructure to better understand why it was performing below the optimal threshold so that we can prevent impact to threat intelligence reports in the SOC in the future.

This is the final update for the event.

Machine Translation タイトル:管理者はセキュリティオペレーションセンター(SOC)での脅威インテリジェンス報告の遅延を目にする可能性がある

ユーザーへの影響:管理者はSOCにおける脅威インテリジェンス報告の遅延を目にした可能性があります。

詳細情報:ユーザーの脅威インテリジェンス報告には3〜5時間の遅延があった可能性があります。

最終状況:前述のバックエンド問題に対応し、影響を受けたデータのバックログの処理完了を確認しました。

影響範囲:この出来事は北米およびヨーロッパの管理者に影響を与え、SOCにおける脅威インテリジェンス報告の遅延を経験した可能性があります。

開始時間:2026年7月9日木曜日 12:00 PM UTC

終了時刻:2026年7月10日金曜日 午前1時30分 UTC

根本原因:この機能で使用されるインフラの一部が最適な閾値を下回り、影響を生んだこと。

次のステップ:
– 影響を受けたインフラ部分を分析し、なぜ最適な閾値以下で動作しているのかをよりよく理解し、将来的にSOCにおける脅威インテリジェンスレポートへの影響を防いでいます。

これがイベントの最終アップデートです。