Skip to content

Commit a0fdfd0

Browse files
authored
Merge branch 'main' into poliveria-ti-naming-09082025
2 parents ee53ed7 + 683dfed commit a0fdfd0

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ ms.service: defender-xdr
66
ms.subservice: adv-hunting
77
f1.keywords:
88
- NOCSH
9-
ms.author: maccruz
10-
author: schmurky
9+
ms.author: pauloliveria
10+
author: poliveria
1111
ms.localizationpriority: medium
12-
manager: dansimp
12+
manager: orspodek
1313
audience: ITPro
1414
ms.collection:
1515
- m365-security
@@ -23,7 +23,7 @@ ms.topic: concept-article
2323
appliesto:
2424
- Microsoft Defender XDR
2525
- Microsoft Sentinel in the Microsoft Defender portal
26-
ms.date: 07/22/2025
26+
ms.date: 09/08/2025
2727
---
2828

2929
# Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
@@ -85,7 +85,6 @@ In the unified portal, in addition to viewing the schema column names and descri
8585

8686
## Known issues
8787

88-
- The `IdentityInfo table` from [Microsoft Sentinel](/azure/sentinel/ueba-reference#identityinfo-table) isn't available, as the `IdentityInfo` table remains as is in Defender XDR. Microsoft Sentinel features like analytics rules that query this table aren't impacted as they're querying the Log Analytics workspace directly.
8988
- The Microsoft Sentinel `SecurityAlert` table is replaced by `AlertInfo` and `AlertEvidence` tables, which both contain all the data on alerts. While SecurityAlert isn't available in the schema tab, you can still use it in queries using the advanced hunting editor. This provision is made so as not to break existing queries from Microsoft Sentinel that use this table.
9089
- Guided hunting mode and take actions capabilities are supported for Defender XDR data only.
9190
- Custom detections have the following limitations:

0 commit comments

Comments
 (0)