You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/dashboard.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -45,7 +45,7 @@ Select links in the cards to just to more details, such as documentation, relate
45
45
|**Identities overview (shield widget)**|Provides a quick overview of the number of users in hybrid, cloud, and on-premises environments (AD and Microsoft Entra ID). This feature includes direct links to the Advanced Hunting platform, offering detailed user information at your fingertips.|
46
46
|**Top insights** /<br>**Users identified in a risky lateral movement path**| Indicates any sensitive accounts with risky lateral movement paths, which are windows of opportunity for attackers and can expose risks. <br><br>We recommend that you take action on any sensitive accounts found with risky lateral movement paths to minimize your risk. <br><br>For more information, see [Understand and investigate Lateral Movement Paths (LMPs) with Microsoft Defender for Identity](understand-lateral-movement-paths.md).|
47
47
|**Top insights** /<br>**Dormant Active Directory users who should be removed from sensitive groups**| Lists accounts that have been left unused for at least 180 days. <br><br>An easy and quiet path deep into your organization is through inactive accounts that are a part of sensitive groups, therefore we recommend removing those users from sensitive groups. <br><br>For more information, see [Security assessment: Riskiest lateral movement paths (LMP)](security-assessment-riskiest-lmp.md).|
48
-
|**ITDR deployment health**| Lists any sensor deployment progress, any health alerts, and license availability. |
48
+
|**ITDR deployment health**| Lists any sensor deployment progress, any health alerts, and license availability derived from Defender for Identity data and Device Inventory, which relies on Defender for Endpoint coverage.|
49
49
|**Identity posture (Secure score)**| The score shown represents your organization's security posture with a focus on the *identity* score, reflecting the collective security state of your identities. The score is automatically updated in real-time to reflect the data shown in graphs and recommended actions. <br><br>Microsoft Secure Score updates daily with system data with new points for each recommended action take.<br><br> For more information, see [Microsoft Secure Score](/microsoft-365/security/defender/microsoft-secure-score). |
50
50
|**Highly privileged entities**| Lists a summary of the sensitive accounts in your organization, including Entra ID security administrators and Global admin users. |
51
51
|**Identity related incidents**| Lists alerts from both Defender for Identity and [Microsoft Entra ID Protection](/azure/active-directory/identity-protection/overview-identity-protection), and any corresponding, relevant incidents from the last 30 days. |
Copy file name to clipboardExpand all lines: ATPDocs/whats-new.md
+1-7Lines changed: 1 addition & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,7 +39,6 @@ Previously, Defender for Identity tenants received Entra ID risk level in the Id
39
39
40
40
For UEBA tenants without a Microsoft Defender for Identity license, synchronization of Entra ID risk level to the IdentityInfo table remains unchanged.
41
41
42
-
43
42
### New security assessment: Remove inactive service accounts (Preview)
44
43
45
44
Microsoft Defender for Identity now includes a new security assessment that helps you identify and remove inactive service accounts in your organization. This assessment lists Active Directory service accounts that have been inactive (stale) for the past 180 days, to help you mitigate security risks associated with unused accounts.
@@ -66,13 +65,12 @@ The new security posture assessment highlights unsecured Active Directory attrib
66
65
67
66
For more information, see: [Security Assessment: Remove discoverable passwords in Active Directory account attributes (Preview)](remove-discoverable-passwords-active-directory-account-attributes.md)
68
67
69
-
70
68
### Microsoft Defender for Identity sensor version updates
71
69
72
70
|Version number |Updates |
73
71
|---------|---------|
74
72
|2.247|Includes bug fixes and stability improvements for the Microsoft Defender for Identity sensor.|
75
-
|2.246|Includes bug fixes and stability improvements for the Microsoft Defender for Identity sensor.|
73
+
|2.246|Includes bug fixes and stability improvements for the Microsoft Defender for Identity sensor.|
76
74
77
75
### Detection update: Suspected Brute Force attack (Kerberos, NTLM)
78
76
@@ -158,10 +156,6 @@ Bug Fixes:
158
156
159
157
## May 2025
160
158
161
-
### Expanded New Sensor Deployment Support for Domain Controllers (Preview)
162
-
Defender for Identity now supports deploying its new sensor on Domain Controllers without requiring Defender for Endpoint onboarding. This simplifies sensor activation and expands deployment flexibility. [Learn more](deploy/activate-sensor.md).
163
-
164
-
165
159
### Improved Visibility into Defender for Identity New Sensor Eligibility in the Activation page
166
160
The Activation Page now displays all servers from your device inventory, including those not currently eligible for the new Defender for Identity sensor. This enhancement increases transparency into sensor eligibility, helping you identify noneligible servers and take action to update and onboard them for enhanced identity protection.
> For portal access, instead of a wildcard (\*), you can choose to open only your specific tenant URL. For example, based on the screenshot above you can open: `contoso.us.portal.cloudappsecurity.com`. To determine your tenant URL, see the earlier section [View your data center](#view-your-data-center), and look for **API URL**.
@@ -166,8 +176,8 @@ To enable Defender for Cloud Apps to connect to your SIEM, add **outbound port 4
0 commit comments