Skip to content

Commit 6ac13cc

Browse files
Merge pull request #4372 from MicrosoftDocs/main
[AutoPublish] main to live - 06/30 01:35 PDT | 06/30 14:05 IST
2 parents 3c68754 + db38bcf commit 6ac13cc

File tree

8 files changed

+71
-7
lines changed

8 files changed

+71
-7
lines changed

ATPDocs/deploy/configure-windows-event-collection.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -235,15 +235,16 @@ To configure domain object auditing:
235235

236236
Now, all relevant changes to directory services appear as 4662 events when they're triggered.
237237

238-
1. Repeat the steps in this procedure, but for **Applies to**, select the following object types:
238+
1. Repeat the steps in this procedure, but for **Applies to**, select the following object types <sup>1</sup>
239239
- **Descendant Group Objects**
240240
- **Descendant Computer Objects**
241241
- **Descendant msDS-GroupManagedServiceAccount Objects**
242242
- **Descendant msDS-ManagedServiceAccount Objects**
243-
- **Descendant msDS-DelegatedManagedServiceAccount Objects**
243+
- **Descendant msDS-DelegatedManagedServiceAccount Objects** <sup>2</sup>
244244

245245
> [!NOTE]
246-
> Assigning the auditing permissions on **All descendant objects** would also work, but you need only the object types detailed in the last step.
246+
> 1. Assigning the auditing permissions on **All descendant objects** would also work, but you need only the object types detailed in the last step.
247+
> 2. The **msDS-DelegatedManagedServiceAccount** class is relevant only for domains running at least one Windows Server 2025 domain controller.
247248
248249
## Configure auditing on AD FS
249250

ATPDocs/identity-inventory.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,7 +110,7 @@ Sort option applies to Display name, Domain, and Created time columns.
110110

111111
- **Critical Active Directory service accounts** card helps you quickly identify all Active Directory accounts designated as critical, making it easier to focus on identities most at risk.
112112

113-
At the top of each device inventory tab, the following device counts are available:
113+
At the top of the page, the following identities counts are available:
114114

115115
- __Total__: The total number of identities.
116116

@@ -120,7 +120,7 @@ At the top of each device inventory tab, the following device counts are availab
120120

121121
- **Services:** The number of all service accounts both on-premises and cloud.
122122

123-
You can use this information to help you prioritize devices for security posture improvements.
123+
You can use this information to help you prioritize identities for security posture improvements.
124124

125125
### Navigate to the Identity inventory page
126126

CloudAppSecurityDocs/governance-actions.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -83,8 +83,7 @@ The following governance actions can be taken for connected apps either on a spe
8383

8484
- **Trash** – Move the file to the trash folder. (Box, Dropbox, Google Drive, OneDrive, SharePoint)
8585

86-
> [!NOTE]
87-
> These actions are restricted to users with specific administrative roles. If the options described are not visible or accessible, please confirm with your system administrator that your account has one of the following roles assigned:
86+
These actions are restricted to users with specific administrative roles. If the options described are not visible or accessible, please confirm with your system administrator that your account has one of the following roles assigned:
8887
- Security Operator
8988
- Security administrator
9089
- Global administrator

unified-secops-platform/TOC.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,9 @@
104104
href: mto-advanced-hunting.md
105105
- name: Multitenant devices
106106
href: mto-tenant-devices.md
107+
- name: Multitenant identities
108+
href: multitenant-identities-inventory.md
109+
displayName: MTO
107110
- name: Vulnerability management
108111
href: mto-dashboard.md
109112
- name: Manage tenants
112 KB
Loading
22.5 KB
Loading
25.7 KB
Loading
Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
---
2+
# Required metadata
3+
# For more information, see https://learn.microsoft.com/en-us/help/platform/learn-editor-add-metadata
4+
# For valid values of ms.service, ms.prod, and ms.topic, see https://learn.microsoft.com/en-us/help/platform/metadata-taxonomies
5+
6+
title: Multitenant identities
7+
description: A multi-tenant identity inventory
8+
author: LiorShapiraa
9+
ms.author: liorshapira
10+
ms.service: microsoft-defender-for-identity
11+
ms.topic: article
12+
ms.date: 06/29/2025
13+
---
14+
15+
# Identities
16+
17+
The **Identities** page in multitenant management enables you to quickly manage tenants and identities.
18+
19+
## Identity inventory
20+
21+
The Identity inventory page lists all the identities in each tenant that you have access to. The page is like the [Defender for Identity inventory](/defender-for-identity/identity-inventory) with the addition of the **Tenant name** column and filter.
22+
23+
You can navigate to the identity inventory page by selecting **Assets > Identities** in Microsoft Defender XDR's navigation menu.
24+
25+
:::image type="content" source="media/multitenant-identities-inventory/screenshot-of-inventory.png" alt-text="Screenshot of inventory." lightbox="media/multitenant-identities-inventory/screenshot-of-inventory.png":::
26+
27+
At the top of the page, the following identities counts are available for all tenants:
28+
29+
**Total**: The total number of identities.
30+
31+
**Critical:** The number of your critical assets.
32+
33+
**Disabled:** The number of all disabled identities in your organization.
34+
35+
**Services:** The number of all service accounts both on-premises and cloud.
36+
37+
You can use this information to help you prioritize identities for security posture improvements.
38+
39+
Highly privileged identities card helps you investigate in Advanced hunting all sensitive accounts in your organization, including Microsoft Entra ID security administrators and Global admin users.
40+
41+
There are several options you can choose from to customize the identities list view. On the top navigation you can:
42+
43+
- Add or remove columns.
44+
45+
- Apply filters.
46+
47+
- Search for an identity by name or full UPN, SID, and Object ID.
48+
49+
- Export the list to a CSV file.
50+
51+
- Copy list link with the included filters configured.
52+
53+
> [!NOTE]
54+
> When exporting the identities list to a CSV file, a maximum of 5,000 identities are displayed.
55+
56+
To view full identity details, select a specific identity from the list. Tenant ID and Tenant name are available in the identity side panel and page:
57+
58+
:::image type="content" source="media/multitenant-identities-inventory/screenshot-of-tenant-details-on-identity.png" alt-text="Screenshot of tenant details on identity.":::
59+
60+
61+

0 commit comments

Comments
 (0)