SHD / MC Checker

MC1461705 | Microsoft Defender XDR: Unified identity timeline on the Identity page



MC1461705 | Microsoft Defender XDR: Unified identity timeline on the Identity page

Classification planForChange
Last Updated 08/25/2026 22:22:05
Start Time 08/25/2026 22:21:58
End Time 11/30/2026 08:00:00
Message Content

[What and Why:]

We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience.

The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks.

[Rollout schedule:]

  • Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026.

[Impact on your organization:]

This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal.

After rollout:

  • The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts.
  • Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available.
  • New filtering and investigation fields will be available, including:

    • Source table
    • Session ID
    • Unique token identifier
    • Conditional Access
    • Target
    • Additional information

  • Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources.
  • The timeline will automatically refresh when linked accounts change.

This update does not modify existing security policies, user accounts, permissions, or configurations.

[Action required / Recommendations:]

No action is required to enable the core timeline experience.

To help your organization take advantage of this enhancement, we recommend that you:

  • Inform SOC and incident response teams about the updated Timeline experience.
  • Review investigation runbooks that require analysts to pivot between multiple Advanced Hunting tables.
  • If you use supported SaaS cloud accounts, enable Identity inventory integration in Microsoft Defender for Cloud Apps by navigating to Settings > Cloud Apps.
  • Confirm that analysts have the appropriate permissions to access identity investigation data in the Microsoft Defender portal.

Learn more

Machine Translation

[何となぜ:]

Microsoft DefenderのIdentityページの タイムライン タブを強化し、セキュリティチームがIDおよびリンクされたアカウントに関連する活動やアラートを一つの時系列で表示できるようにします。この強化により、複数のMicrosoftセキュリティデータソースからの関連イベントを一つの調査体験に統合することで、セキュリティオペレーションセンター(SOC)のアナリスト、インシデント対応者、セキュリティ管理者がより効率的にアイデンティティを調査できます。

更新されたタイムラインは、Microsoft Entraのサインイン、Microsoft Graph監査イベント、SaaSクラウド活動、デバイスロゴンなどの統合されたセキュリティ製品の活動を正規化します。追加の調査コンテキスト、フィルタリング機能、イベント詳細により、アナリストはアイデンティティ関連の活動やセキュリティリスクをより迅速に理解できます。

[展開スケジュール:]

  • 世界規模、GCC、GCCハイ、国防総省: 展開は2026年9月中旬から始まり、2026年10月中旬までに完了する見込みです。

[組織への影響:]

このアップデートは、Microsoft Defenderポータルで身元を調査するSOCアナリスト、インシデント対応者、セキュリティ管理者に影響を与えます。

展開後:

  • Identityページの タイムライン タブでは、IDおよびその連携アカウントの活動とアラートの統合された順序が表示されます。
  • Microsoft EntraのサインインやMicrosoft Graph監査イベントでは、利用可能な場合に関連するリスク情報や条件付きアクセス情報が含まれます。
  • 新しいフィルタリングおよび調査フィールドが利用可能になります。以下が含まれます:

    • 出典表
    • セッションID
    • 一意トークン識別子
    • 条件付きアクセス
    • ターゲット
    • 追加情報

  • 拡張されたイベントコンテキストは、複数のデータソースをまたぐことなく、アナリストがアイデンティティ関連の活動を調査するのに役立ちます。
  • 連携したアカウントが変わると、タイムラインは自動的に更新されます。

このアップデートは既存のセキュリティポリシー、ユーザーアカウント、権限、設定を変更するものではありません。

[必要な行動/推奨事項:]

コアタイムライン体験を有効にするためにアクションは必要ありません。

この強化を組織が活用するために、以下のことをお勧めします:

  • 更新されたタイムライン体験についてSOCおよびインシデント対応チームに知らせてください。
  • 複数のAdvanced Huntingテーブルを行き来する必要がある調査ランブックを見直しましょう。
  • サポートされているSaaSクラウドアカウントを使用している場合は、Microsoft Defender for Cloud Appsの 「Cloud Appsの設定」からIdentity inventory統合を有効にしてください>
  • アナリストがMicrosoft DefenderポータルのID調査データにアクセスするための適切な権限を持っているか確認してください。

詳しくはこちら