Microsoft Defender for Identity: Unified identity timeline on the Identity page
🚨 The Signal: Microsoft Defender for Identity now offers a unified timeline for identity-related activities and alerts, integrating data from various Microsoft security products. This centralises visibility for security teams, improving threat detection and investigation efficiency.
The Impact
Security teams are affected by enhanced identity visibility, reducing the risk of undetected identity-based attacks.
- Security Analysts: Reduced time to detect and respond to identity-based threats.
- Incident Responders: Improved context for investigating compromised identities.
- Security Operations Center (SOC): Enhanced ability to correlate diverse identity signals.
The Action
- Navigate to Microsoft Defender XDR portal > Identities.
- Select an identity to view the unified timeline.
- Familiarise security teams with new filters (Source table, Session ID, Unique token identifier) for enhanced investigation.
Domain: Defender · Impact: medium · Workload: Microsoft Defender