Skip to content

Commit 683dfed

Browse files
authored
Merge pull request #4957 from MicrosoftDocs/poliveria-ah-mdi-09082025
Update metadata and known issues in hunting guide
2 parents 7bf2d70 + 95fd737 commit 683dfed

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ ms.service: defender-xdr
66
ms.subservice: adv-hunting
77
f1.keywords:
88
- NOCSH
9-
ms.author: maccruz
10-
author: schmurky
9+
ms.author: pauloliveria
10+
author: poliveria
1111
ms.localizationpriority: medium
12-
manager: dansimp
12+
manager: orspodek
1313
audience: ITPro
1414
ms.collection:
1515
- m365-security
@@ -23,7 +23,7 @@ ms.topic: concept-article
2323
appliesto:
2424
- Microsoft Defender XDR
2525
- Microsoft Sentinel in the Microsoft Defender portal
26-
ms.date: 07/22/2025
26+
ms.date: 09/08/2025
2727
---
2828

2929
# Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
@@ -85,7 +85,6 @@ In the unified portal, in addition to viewing the schema column names and descri
8585

8686
## Known issues
8787

88-
- The `IdentityInfo table` from [Microsoft Sentinel](/azure/sentinel/ueba-reference#identityinfo-table) isn't available, as the `IdentityInfo` table remains as is in Defender XDR. Microsoft Sentinel features like analytics rules that query this table aren't impacted as they're querying the Log Analytics workspace directly.
8988
- The Microsoft Sentinel `SecurityAlert` table is replaced by `AlertInfo` and `AlertEvidence` tables, which both contain all the data on alerts. While SecurityAlert isn't available in the schema tab, you can still use it in queries using the advanced hunting editor. This provision is made so as not to break existing queries from Microsoft Sentinel that use this table.
9089
- Guided hunting mode and take actions capabilities are supported for Defender XDR data only.
9190
- Custom detections have the following limitations:

0 commit comments

Comments
 (0)