| MC1461705 | Microsoft Defender XDR: Unified identity timeline on the Identity page |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 08/25/2026 22:22:05 |
| Start Time | 08/25/2026 22:21:58 |
| End Time | 11/30/2026 08:00:00 |
| Message Content |
[What and Why:] We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience. The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks. [Rollout schedule:]
[Impact on your organization:] This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal. After rollout:
This update does not modify existing security policies, user accounts, permissions, or configurations. [Action required / Recommendations:] No action is required to enable the core timeline experience. To help your organization take advantage of this enhancement, we recommend that you:
Learn more |
| Machine Translation |
[何となぜ:] Microsoft DefenderのIdentityページの タイムライン タブを強化し、セキュリティチームがIDおよびリンクされたアカウントに関連する活動やアラートを一つの時系列で表示できるようにします。この強化により、複数のMicrosoftセキュリティデータソースからの関連イベントを一つの調査体験に統合することで、セキュリティオペレーションセンター(SOC)のアナリスト、インシデント対応者、セキュリティ管理者がより効率的にアイデンティティを調査できます。 更新されたタイムラインは、Microsoft Entraのサインイン、Microsoft Graph監査イベント、SaaSクラウド活動、デバイスロゴンなどの統合されたセキュリティ製品の活動を正規化します。追加の調査コンテキスト、フィルタリング機能、イベント詳細により、アナリストはアイデンティティ関連の活動やセキュリティリスクをより迅速に理解できます。 [展開スケジュール:]
[組織への影響:] このアップデートは、Microsoft Defenderポータルで身元を調査するSOCアナリスト、インシデント対応者、セキュリティ管理者に影響を与えます。 展開後:
このアップデートは既存のセキュリティポリシー、ユーザーアカウント、権限、設定を変更するものではありません。 [必要な行動/推奨事項:] コアタイムライン体験を有効にするためにアクションは必要ありません。 この強化を組織が活用するために、以下のことをお勧めします:
詳しくはこちら
|