Skip to content

Commit e4d8a20

Browse files
committed
near real time updates for Entra ID Risk Level
1 parent 33f7fdd commit e4d8a20

File tree

2 files changed

+13
-1
lines changed

2 files changed

+13
-1
lines changed

ATPDocs/whats-new.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,14 @@ For updates about versions and features released six months ago or earlier, see
2525

2626
## August 2025
2727

28+
### Microsoft Entra ID risk level near-real-time (NRT) visibility in Defender for Identity (Preview)
29+
30+
Microsoft Entra ID Risk Level extends identity visibility in Identity Inventory assets page, the Identity page, and the Identity Info Table in Advanced Hunting to include the Entra ID risk score. It lets SOC analysts correlate risky users and sensitive and high-privileged users, and create custom detections based on current or historical user risk to enhance investigation context.
31+
32+
Previously, Microsoft Defender for Identity tenants received Entra ID Risk Level attributes in the Identity Info Table through UEBA. With this update, these attributes will now be synchronized in near real time via Defender for Identity.
33+
34+
For UEBA tenants without a Microsoft Defender for Identity license, the Entra ID Risk Level sync to the Identity Info table remains unchanged.
35+
2836

2937
## New security posture assessment: Remove discoverable passwords in Active Directory account attributes (Preview)
3038

defender-xdr/advanced-hunting-identityinfo-table.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,10 +102,14 @@ If you're using the Microsoft Defender portal but haven't onboarded a Microsoft
102102
- `DeletedDateTime`
103103
- `EmployeeId`
104104
- `OtherMailAddresses`
105+
- `Tags`
106+
107+
The following columns are available in near real time for tenants with Microsoft Defender for Identity:
108+
105109
- `RiskLevel`
106110
- `RiskLevelDetails`
107111
- `State`
108-
- `Tags`
112+
109113

110114
For more information about UEBA, read [Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel](/azure/sentinel/identify-threats-with-entity-behavior-analytics). For more information about the different data sources in UEBA, read [Microsoft Sentinel UEBA reference](/azure/sentinel/ueba-reference).
111115

0 commit comments

Comments
 (0)