From 1a89e1f72fd053060657a0adf7e55454e7a0ae0a Mon Sep 17 00:00:00 2001 From: amitkumart <126546958+amitkumart@users.noreply.github.com> Date: Wed, 6 Aug 2025 15:45:57 +0530 Subject: [PATCH] Update investigate-user.md --- defender-endpoint/investigate-user.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/defender-endpoint/investigate-user.md b/defender-endpoint/investigate-user.md index 768b6291d2..f7bf2cf086 100644 --- a/defender-endpoint/investigate-user.md +++ b/defender-endpoint/investigate-user.md @@ -62,6 +62,9 @@ The Overview, Alerts, and Observed in organization are different tabs that displ > [!NOTE] > For Linux devices, information about logged in users is not displayed. +> [!NOTE] +> Microsoft Defender for Business does not include Microsoft Defender for Identity (MDI) by default. In SMB-based environments, Logon User data will not be available unless MDI sensors are installed. To ensure visibility into logon events, customers must deploy MDI sensors. + ### Overview The **Overview** tab shows the incidents details and a list of the devices that the user has logged on to. You can expand these to see details of the log-on events for each device.