Skip to content

Commit 994c41a

Browse files
Merge pull request #4747 from DeCohen/WI480943-near-real-time-updates-entra-id-risk-level
near real time updates for Entra ID Risk Level
2 parents c979609 + f599270 commit 994c41a

File tree

2 files changed

+10
-3
lines changed

2 files changed

+10
-3
lines changed

ATPDocs/whats-new.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,14 @@ For updates about versions and features released six months ago or earlier, see
2525

2626
## August 2025
2727

28+
### Microsoft Entra ID risk level is now available in near real time in Microsoft Defender for Identity (Preview)
29+
30+
Entra ID risk level is now available on the Identity Inventory assets page, the identity details page, and in the IdentityInfo table in Advanced Hunting, and includes the Entra ID risk score. SOC analysts can use this data to correlate risky users with sensitive or highly privileged users, create custom detections based on current or historical user risk, and improve investigation context.
31+
32+
Previously, Defender for Identity tenants received Entra ID risk level in the IdentityInfo table through user and entity behavior analytics (UEBA). With this update, the Entra ID risk level is now updated in near real time through Microsoft Defender for Identity.
33+
34+
For UEBA tenants without a Microsoft Defender for Identity license, synchronization of Entra ID risk level to the IdentityInfo table remains unchanged.
35+
2836

2937
### New security assessment: Remove inactive service accounts (Preview)
3038

defender-xdr/advanced-hunting-identityinfo-table.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -102,10 +102,9 @@ If you're using the Microsoft Defender portal but haven't onboarded a Microsoft
102102
- `DeletedDateTime`
103103
- `EmployeeId`
104104
- `OtherMailAddresses`
105-
- `RiskLevel`
106-
- `RiskLevelDetails`
107-
- `State`
108105
- `Tags`
106+
- `State`
107+
109108

110109
For more information about UEBA, read [Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel](/azure/sentinel/identify-threats-with-entity-behavior-analytics). For more information about the different data sources in UEBA, read [Microsoft Sentinel UEBA reference](/azure/sentinel/ueba-reference).
111110

0 commit comments

Comments
 (0)