Skip to content

Commit c78f030

Browse files
committed
More updates
1 parent 8d4358a commit c78f030

6 files changed

+22
-10
lines changed

defender-xdr/advanced-hunting-datasecuritybehaviors-table.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,9 +38,9 @@ The `DataSecurityBehaviors` table in the [advanced hunting](advanced-hunting-ove
3838

3939
Insights cover a range of data security related behaviors like behaviors involving exfiltration, obfuscation, risky interactions with AI applications, and others. Insights are generated by aggregating user behaviors over a calendar day and comparing them with previous activity, peer group activity, or other activities done by the user. Insights also capture summaries of various risk pivots like sensitive data, risky destinations, and the like.
4040

41-
Use this reference to construct queries that return information from this table.
41+
This advanced hunting table is populated by records from Microsoft Purview Insider Risk Management. If your organization hasn’t opted in to share insider risk alerts with Microsoft Defender XDR, queries that use the table aren’t going to work or return any results. For more information, read [Investigate insider risk threats](irm-investigate-alerts-defender.md).
4242

43-
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
43+
Use this reference to construct queries that return information from this table. For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
4444

4545
| Column name | Data type | Description |
4646
|-------------|-----------|-------------|

defender-xdr/advanced-hunting-datasecurityevents-table.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,9 @@ ms.date: 03/28/2025
3535
3636
The `DataSecurityEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about user activities that violate user-defined or default policies in the Microsoft Purview suite of solutions. Each log represents a single user activity enriched with proprietary Microsoft detections (like sensitive info types) and user-defined enrichment labels like domain categories, sensitivity labels, and others.
3737

38-
Use this reference to construct queries that return information from this table.
38+
This advanced hunting table is populated by records from Microsoft Purview Insider Risk Management. If your organization hasn’t opted in to share insider risk alerts with Microsoft Defender XDR, queries that use the table aren’t going to work or return any results. For more information, read [Investigate insider risk threats](irm-investigate-alerts-defender.md).
3939

40-
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
40+
Use this reference to construct queries that return information from this table. For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
4141

4242
| Column name | Data type | Description |
4343
|-------------|-----------|-------------|

defender-xdr/advanced-hunting-identitydirectoryevents-table.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,8 @@ ms.date: 03/28/2025
3232

3333
The `IdentityDirectoryEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains events involving an on-premises domain controller running Active Directory (AD). This table captures various identity-related events, like password changes, password expiration, and user principal name (UPN) changes. It also captures system events on the domain controller, like scheduling of tasks and PowerShell activity. Use this reference to construct queries that return information from this table.
3434

35+
This advanced hunting table is populated by records from Microsoft Defender for Identity. If your organization hasn’t deployed the service in Microsoft Defender XDR,queries that use the table aren’t going to work or return any results. For more information about how to deploy Defender for Identity in Defender XDR, read [Deploy supported services](deploy-supported-services.md).
36+
3537
> [!TIP]
3638
> For detailed information about the events types (`ActionType` values) supported by a table, use the built-in schema reference available in Microsoft Defender XDR.
3739

defender-xdr/advanced-hunting-messageevents-table.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,9 @@ ms.collection:
1717
ms.custom:
1818
- cx-ti
1919
- cx-ah
20-
appliesto:
21-
- Microsoft Defender XDR
20+
appliesto:
21+
- Microsoft Defender XDR
22+
- Microsoft Sentinel in the Microsoft Defender portal
2223
ms.topic: reference
2324
ms.date: 03/18/2025
2425
---
@@ -32,6 +33,8 @@ ms.date: 03/18/2025
3233
3334
The `MessageEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains details about messages sent and received within your organization at the time of delivery. Use this reference to construct queries that return information from this table.
3435

36+
This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn’t deployed the service in Microsoft Defender XDR,queries that use the table aren’t going to work or return any results. For more information about how to deploy Defender for Office 365 in Defender XDR, read [Deploy supported services](https://learn.microsoft.com/en-us/defender-xdr/deploy-supported-services).
37+
3538

3639
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
3740

defender-xdr/advanced-hunting-messagepostdeliveryevents-table.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,9 @@ ms.collection:
1717
ms.custom:
1818
- cx-ti
1919
- cx-ah
20-
appliesto:
21-
- Microsoft Defender XDR
20+
appliesto:
21+
- Microsoft Defender XDR
22+
- Microsoft Sentinel in the Microsoft Defender portal
2223
ms.topic: reference
2324
ms.date: 03/18/2025
2425
---
@@ -32,6 +33,9 @@ ms.date: 03/18/2025
3233
3334
The `MessagePostDeliveryEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization.
3435

36+
This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn’t deployed the service in Microsoft Defender XDR,queries that use the table aren’t going to work or return any results. For more information about how to deploy Defender for Office 365 in Defender XDR, read [Deploy supported services](https://learn.microsoft.com/en-us/defender-xdr/deploy-supported-services).
37+
38+
3539
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
3640

3741
| Column name | Data type | Description |

defender-xdr/advanced-hunting-messageurlinfo-table.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,9 @@ ms.collection:
1717
ms.custom:
1818
- cx-ti
1919
- cx-ah
20-
appliesto:
21-
- Microsoft Defender XDR
20+
appliesto:
21+
- Microsoft Defender XDR
22+
- Microsoft Sentinel in the Microsoft Defender portal
2223
ms.topic: reference
2324
ms.date: 03/18/2025
2425
---
@@ -32,6 +33,8 @@ ms.date: 03/18/2025
3233
3334
The `MessageUrlInfo` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about URLs sent through Microsoft Teams messages in your organization.
3435

36+
This advanced hunting table is populated by records from Microsoft Defender for Office 365. If your organization hasn’t deployed the service in Microsoft Defender XDR,queries that use the table aren’t going to work or return any results. For more information about how to deploy Defender for Office 365 in Defender XDR, read [Deploy supported services](https://learn.microsoft.com/en-us/defender-xdr/deploy-supported-services).
37+
3538
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
3639

3740
| Column name | Data type | Description |

0 commit comments

Comments
 (0)