Skip to content

Commit 65ee746

Browse files
authored
Merge pull request #206694 from yelevin/patch-2
Added AD/MDI sync
2 parents d14cc90 + 0daf247 commit 65ee746

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

articles/sentinel/whats-new.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,19 @@ If you're looking for items older than six months, you'll find them in the [Arch
2929
3030
## July 2022
3131

32+
- [Sync user entities from your on-premises Active Directory with Microsoft Sentinel](#sync-user-entities-from-your-on-premises-active-directory-with-microsoft-sentinel)
3233
- [Automation rules for alerts](#automation-rules-for-alerts)
3334

35+
### Sync user entities from your on-premises Active Directory with Microsoft Sentinel
36+
37+
Until now, you've been able to bring your user account entities from your Azure Active Directory (Azure AD) into the IdentityInfo table in Microsoft Sentinel, so that User and Entity Behavior Analytics (UEBA) can use that information to provide context and give insight into user activities, to enrich your investigations.
38+
39+
Now you can do the same with your on-premises (non-Azure) Active Directory as well.
40+
41+
If you have Microsoft Defender for Identity, [enable and configure User and Entity Behavior Analytics (UEBA)](enable-entity-behavior-analytics.md#how-to-enable-user-and-entity-behavior-analytics) to collect and sync your Active Directory user account information into Microsoft Sentinel's IdentityInfo table, so you can get the same insight value from your on-premises users as you do from your cloud users.
42+
43+
Learn more about the [requirements for using Microsoft Defender for Identity](/defender-for-identity/prerequisites) this way.
44+
3445
### Automation rules for alerts
3546

3647
In addition to their incident-management duties, [automation rules](automate-incident-handling-with-automation-rules.md) have a new, added function: they are the preferred mechanism for running playbooks built on the **alert trigger**.

0 commit comments

Comments
 (0)