MC1187386 – Microsoft Defender for Identity alerts transitioning to XDR-based detection platform (archived)

cloudscout.one Icon

check before: 2025-12-15

Product:

Defender, Defender for Identity, Defender XDR

Platform:

Online, US Instances, World tenant

Status:

Change type:

Feature update, Admin impact

Links:

Details:

Summary:
Microsoft Defender for Identity classic alerts will transition to the XDR detection platform starting mid-December 2025, improving detection accuracy. Admins must update workflows, use new Detector IDs, and reconfigure alert exclusions with XDR Alert Tuning rules. The rollout completes by early January 2026.

Details:
[Introduction]
Microsoft Defender for Identity classic alerts will transition to the XDR detection platform in mid-December 2025. This change improves detection accuracy and performance and aligns with our efforts to enhance security across environments.
[When this will happen:]
General availability (Production, GCC, and DoD): Rollout will begin in mid-December 2025 and is expected to complete early January.

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:

Created:
2025-11-18

updated:
2025-11-18

Task Type

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS How does it affect me

XXXXXXX ... free basic plan only

MS Preperations

XXXXXXX ... free basic plan only

MS Urgency

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

summary for non-techies**

The library is upgrading its security system to a smarter XDR detection platform, requiring administrators to update workflows, Detector IDs, and alert tuning rules by January 2026 to enhance threat detection and response.

Direct effects for Operations**

Workflow Disruption
Admins may face disruptions in their alert management workflows due to the transition to new Detector IDs, leading to potential delays in incident response.
   - roles: Security Admin, IT Operations Manager
   - references: https://techcommunity.microsoft.com/t5/security-compliance-identity/microsoft-defender-for-identity-alerts-transitioning-to-xdr/ba-p/3751230

Increased False Positives
Without proper reconfiguration of alert exclusions, there may be an increase in false positives, causing unnecessary alerts and potential alert fatigue among security teams.
   - roles: Security Analyst, Incident Response Team
   - references: https://techcommunity.microsoft.com/t5/security-compliance-identity/microsoft-defender-for-identity-alerts-transitioning-to-xdr/ba-p/3751230

User Experience Degradation
End users may experience delays in response to security incidents if alerts are not properly managed, leading to potential security vulnerabilities.
   - roles: End User, Help Desk Support
   - references: https://techcommunity.microsoft.com/t5/security-compliance-identity/microsoft-defender-for-identity-alerts-transitioning-to-xdr/ba-p/3751230

Configutation Options**

XXXXXXX ... paid membership only

Opportunities**

XXXXXXX ... free basic plan only

Potentional Risks**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



Last updated 2 weeks ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!