Microsoft Defender XDR
General

Entity Page Device

In brief

The documentation now specifies that custom activity data mapped from Sentinel to Microsoft Defender XDR must include either HostName plus NTDomain or HostName plus DnsDomain.

What Defender admins need to know

Ensure ingested custom activity data includes one of these identifier combinations for correct Device Timeline visibility.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For more information about these activity events, see Entity pages in Microsoft Sentinel.

Strong identifier requirements for unified timeline (Sentinel to XDR mapping)

To ensure that custom activity data (for example, Sophos alerts) is correctly mapped and visible in Microsoft Defender XDR (security.microsoft.com) under the Device Timeline, the ingested data must include a strong identifier combination for the host.

Required strong identifiers

At a minimum, include one of the following strong identifier combinations:

  • HostName + NTDomain
  • HostName + DnsDomain