SHD / MC Checker

MC1461704 | Microsoft Defender XDR: Unified response actions across identity accounts



MC1461704 | Microsoft Defender XDR: Unified response actions across identity accounts

Classification planForChange
Last Updated 08/25/2026 22:21:35
Start Time 08/25/2026 22:21:28
End Time 12/21/2026 08:00:00
Message Content

[What and why:]

Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts.
Security teams will be able to apply supported response actions to all supported accounts associated with an identity,
or to selected accounts, from a single workflow.

Available actions depend on the identity system or connector managing the account and may include:

  • Disable account
  • Enable account
  • Revoke session
  • Mark as compromised
  • Force password change

Supported identity systems and applications include:

  • Active Directory
  • Microsoft Entra ID
  • Okta
  • CyberArk Identity
  • SailPoint Identity Security Cloud
  • Google Workspace
  • Salesforce
  • Box

This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications.

[Rollout schedule:]

  • Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026.

Who is affected

  • Security Operations Center (SOC) analysts
  • Incident responders
  • Identity administrators
  • Administrators managing Microsoft Defender-connected identity systems

Platforms and services

  • Microsoft Defender XDR
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Entra ID
  • Supported third-party identity provider and SaaS application connectors

What will happen

  • Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center.
  • Available response actions vary based on the identity system or connector managing each account.
  • Administrators can review action status in Action center and in audit records generated by the target system.
  • No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action.

[Action required / Recommendations:]

No action is required to enable this capability. However, we recommend that administrators:

  • Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles.
  • Verify Microsoft Defender for Identity action account configuration for Active Directory response actions.
  • If using Microsoft Defender for Identity sensor version 3.x, ensure the sensor is running under the Local System account.
  • Verify that supported identity provider and SaaS application connectors are configured with credentials that allow the intended response actions.
  • Enable Identity Inventory integration in Microsoft Defender for Cloud Apps if SaaS cloud accounts are included in response workflows.
  • Update incident response runbooks and train analysts to verify selected accounts before confirming response actions.

Learn more

Machine Translation

[何を、なぜ:]

Microsoft Defender XDRは、連結されたアカウント間でアイデンティティ応答アクションを統合された体験に拡張しています。
セキュリティチームは、IDに関連するすべてのサポートアカウントに対してサポート応答アクションを適用できるようになります。
または、単一のワークフローから選択されたアカウントへ。

利用可能なアクションは、アカウントを管理するアイデンティティシステムまたはコネクタに依存し、以下のようなものが含まれる場合があります:

  • アカウントを無効にする
  • アカウントを有効にする
  • 取り消しセッション
  • マークは侵害されたとされる
  • パスワード変更を強制する

サポートされているアイデンティティシステムおよびアプリケーションには以下が含まれます:

  • アクティブディレクトリ
  • Microsoft Entra ID
  • オクタ
  • サイバーアーク・アイデンティティ
  • SailPoint アイデンティティセキュリティクラウド
  • Google Workspace
  • Salesforce
  • ボックス

この強化により、セキュリティ運用チームは接続されたアイデンティティプロバイダーやSaaSアプリケーション間で、侵害されたアイデンティティに対してより迅速かつ一貫して対応できるようになります。

[展開スケジュール:]

  • 世界規模、GCC、GCCハイ、国防総省: 展開は2026年10月中旬に始まり、2026年10月中旬までに完了する予定です。

影響を受ける人物

  • セキュリティオペレーションセンター(SOC)アナリスト
  • インシデント対応者
  • アイデンティティ管理者
  • Microsoft Defender接続型アイデンティティシステムを管理する管理者

ホームとサービス

  • Microsoft Defender XDR
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Entra ID
  • サポートされるサードパーティのアイデンティティプロバイダーおよびSaaSアプリケーションコネクタ

何が起こるのか

  • 認定アナリストは、アイデンティティページ、アイデンティティサイドパネル、アドバンスドハンティング、またはアクションセンターからサポート応答アクションを開始できます。
  • 利用可能な応答アクションは、各アカウントを管理するアイデンティティシステムやコネクタによって異なります。
  • 管理者はアクションセンターやターゲットシステムが生成する監査記録でアクション状況を確認できます。
  • 認可されたアナリストが応答アクションを開始するか、Microsoft Defender Automatic Attack Disruptionが対応可能な自動応答アクションを適用しない限り、アカウント変更は起こりません。

[必要な行動/推奨事項:]

この機能を有効にするために何らかの措置は必要ありません。ただし、管理者には以下のことを推奨します:

  • 必要なMicrosoft Defender Unified RBAC権限とMicrosoft Entraの役割を確認し、割り当ててください。
  • Active DirectoryのレスポンスアクションのためにMicrosoft Defender for Identityアクションのアカウント設定を確認してください。
  • Microsoft Defender for Identityセンサーバージョン3.xを使用している場合は、センサーがローカルシステムアカウントで動作していることを確認してください。
  • サポートされているアイデンティティプロバイダーおよびSaaSアプリケーションコネクターが、意図した応答アクションを可能にする認証情報で設定されているか確認してください。
  • SaaSクラウドアカウントがレスポンスワークフローに含まれている場合、Microsoft Defender for Cloud AppsでIdentity Inventory統合を有効にしてください。
  • インシデント対応ランブックを更新し、アナリストに対応行動を確定する前に選択したアカウントの検証を訓練してください。

詳しくはこちら