You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/remove-discoverable-passwords-active-directory-account-attributes.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
---
2
2
title: 'Security Assessment: Remove Discoverable Passwords in Active Directory Account Attributes (Preview)'
3
3
description: Learn how to identify and address discoverable passwords in Active Directory account attributes to mitigate security risks and improve your organization's security posture.
4
-
ms.date: 08/04/2025
4
+
ms.date: 08/12/2025
5
5
ms.topic: how-to
6
6
---
7
7
@@ -10,7 +10,7 @@ ms.topic: how-to
10
10
11
11
## Why do discoverable passwords in Active Directory account attributes pose a risk?
12
12
13
-
Certain free-text attributes are often overlooked during hardening but are readable by any authenticated user in the domain. When credentials or clues are mistakenly stored in these attributes, attackers can abuse them to move laterally across the environment or escalate privileges—often without triggering traditional alerts.
13
+
Certain free-text attributes are often overlooked during hardening but are readable by any authenticated user in the domain. When credentials or clues are mistakenly stored in these attributes, attackers can abuse them to move laterally across the environment or escalate privileges.
14
14
15
15
Attackers seek low-friction paths to expand access. Exposed passwords in these attributes represent an easy win because:
16
16
@@ -26,12 +26,12 @@ Removing exposed credentials from these attributes reduces the risk of identity
26
26
## How does Microsoft Defender for Identity detect discoverable passwords?
27
27
28
28
> [!NOTE]
29
-
> This security recommendation is part of Microsoft Defender for Identity and is powered by AI-based analysis of free-text attributes in Active Directory.
30
29
> Findings can include false positives. Always validate the results before taking action.
31
30
32
-
Microsoft Defender for Identity detects potential credential exposure in Active Directory by analyzing commonly used free-text attributes. This includes looking for common password formats, hints, `'description'`, `'info'`, and `'adminComment'` fields, and other contextual clues that might suggest the presence of credential misuse. Microsoft Defender for Identity detects indicators such as:
31
+
Microsoft Defender for Identity detects potential credential exposure in Active Directory by analyzing commonly used free-text attributes. This includes looking for common password formats, hints, `'description'`, `'info'`, and `'adminComment'` fields, and other contextual clues that might suggest the presence of credential misuse.
32
+
This recommendation uses GenAI-powered analysis of Active directory attributes to detect:
33
33
34
-
- Plaintext passwords or variations. For example, '`Password=Summer2024!'`
34
+
- Plaintext passwords or variations. For example, '`Password=Summer2025!'`
35
35
36
36
- Credential patterns, reset hints, or sensitive account information.
Copy file name to clipboardExpand all lines: defender-endpoint/ios-whatsnew.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ ms.author: ewalsh
6
6
author: emmwalshh
7
7
ms.reviewer: sunasing; denishdonga
8
8
ms.localizationpriority: medium
9
-
ms.date: 05/15/2025
9
+
ms.date: 08/12/2025
10
10
manager: deniseb
11
11
audience: ITPro
12
12
ms.collection:
@@ -125,7 +125,7 @@ Defender for Endpoint is ending support for iOS/iPadOS 15 on January 31, 2025. M
125
125
126
126
**How does this affect you or your users?**
127
127
128
-
New users won't be able to install the Microsoft Defender app on devices running iOS/iPadOS 15 and earlier versions. Similarly, existing users won't be to upgrade to the latest version of the app.
128
+
New users won't be able to install the Microsoft Defender app on devices running iOS/iPadOS 15 and earlier versions. Similarly, existing users will be able to upgrade till April-Mid Release version (1.1.64030101) of the app and not beyond it.
129
129
130
130
To check which devices support iOS 16 or iPadOS 16 (if applicable), see the following Apple documentation:
Copy file name to clipboardExpand all lines: defender-endpoint/whats-new-in-microsoft-defender-endpoint.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -49,6 +49,7 @@ For more information on what's new with other Microsoft Defender security produc
49
49
## July 2025
50
50
51
51
- (GA) [Microsoft Defender Core service](/defender-endpoint/microsoft-defender-core-service-overview) is now generally available on Windows Server 2019 or later. Helps with the stability and performance of Microsoft Defender Antivirus.
52
+
- Support for Azure Stack HCI OS is rolling out across commercial and government clouds.
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
33
-
34
31
The `MessageEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains details about messages sent and received within your organization at the time of delivery. Use this reference to construct queries that return information from this table.
35
32
36
33
This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn’t deployed the service in Microsoft Defender XDR, queries that use the table aren’t going to work or return any results. For more information about how to deploy Defender for Office 365 in Defender XDR, read [Deploy supported services](deploy-supported-services.md).
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
31
+
33
32
34
33
The `MessagePostDeliveryEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization.
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-schema-tables.md
+5-4Lines changed: 5 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,7 +21,7 @@ appliesto:
21
21
- Microsoft Defender XDR
22
22
- Microsoft Sentinel in the Microsoft Defender portal
23
23
ms.topic: reference
24
-
ms.date: 08/05/2025
24
+
ms.date: 08/13/2025
25
25
---
26
26
27
27
# Understand the advanced hunting schema
@@ -104,9 +104,9 @@ The following reference lists all the tables in the schema. Each table name link
104
104
|**[IdentityInfo](advanced-hunting-identityinfo-table.md)**| Account information from various sources, including Microsoft Entra ID |
105
105
|**[IdentityLogonEvents](advanced-hunting-identitylogonevents-table.md)**| Authentication events on Active Directory and Microsoft online services |
106
106
|**[IdentityQueryEvents](advanced-hunting-identityqueryevents-table.md)**| Queries for Active Directory objects, such as users, groups, devices, and domains |
107
-
|**[MessageEvents](advanced-hunting-messageevents-table.md)**(Preview) | Messages sent and received within your organization at the time of delivery |
108
-
|**[MessagePostDeliveryEvents](advanced-hunting-messagepostdeliveryevents-table.md)**(Preview)| Security events that occurred after the delivery of a Microsoft Teams message in your organization |
109
-
|**[MessageUrlInfo](advanced-hunting-messageurlinfo-table.md)**(Preview) | URLs sent through Microsoft Teams messages in your organization |
107
+
|**[MessageEvents](advanced-hunting-messageevents-table.md)**| Messages sent and received within your organization at the time of delivery |
108
+
|**[MessagePostDeliveryEvents](advanced-hunting-messagepostdeliveryevents-table.md)**| Security events that occurred after the delivery of a Microsoft Teams message in your organization |
109
+
|**[MessageUrlInfo](advanced-hunting-messageurlinfo-table.md)**| URLs sent through Microsoft Teams messages in your organization |
110
110
|**[OAuthAppInfo](advanced-hunting-oauthappinfo-table.md)** (Preview) | Microsoft 365-connected OAuth applications registered with Microsoft Entra ID and available in the Defender for Cloud Apps app governance capability |
111
111
|**[UrlClickEvents](advanced-hunting-urlclickevents-table.md)**| Safe Links clicks from email messages, Teams, and Office 365 apps |
112
112
@@ -117,4 +117,5 @@ The following reference lists all the tables in the schema. Each table name link
Copy file name to clipboardExpand all lines: unified-secops-platform/microsoft-sentinel-onboard.md
+3Lines changed: 3 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -161,6 +161,8 @@ When you switch the primary workspace for Microsoft Sentinel, the Defender XDR c
161
161
162
162
If you decide to offboard a workspace from the Defender portal, disconnect the workspace from the settings for Microsoft Sentinel.
163
163
164
+
If your workspace has the [Microsoft Defender XDR connector](/azure/sentinel/connect-microsoft-365-defender) configured, offboarding the workspace from the Defender portal will also disconnect the Microsoft Defender XDR connector.
165
+
164
166
1. Go to the [Microsoft Defender portal](https://security.microsoft.com/) and sign in.
165
167
1. In the Defender portal, under **System**, select **Settings** > **Microsoft Sentinel**.
166
168
1. On the **Workspaces** page, select the connected workspace and **Disconnect workspace**.
@@ -178,3 +180,4 @@ If you want to connect to a different workspace, from the **Workspaces** page, s
178
180
-[Automatic attack disruption in Microsoft Defender XDR](/defender-xdr/automatic-attack-disruption)
179
181
-[Investigate incidents in Microsoft Defender portal](/defender-xdr/investigate-incidents)
180
182
-[Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access?tabs=defender-portal)
0 commit comments