Microsoft Defender for Identity
Identity protection

Account correlation rules in Microsoft Defender for Identity (Preview)

In brief

The article was retitled and expanded with guidance for adding, editing, and removing account correlation rules, plus a settings screenshot and clearer license and role prerequisites.

What Defender admins need to know

Administrators can use the updated steps and prerequisites to manage these rules in the Microsoft Defender portal.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create customManage account correlation rules in Microsoft Defender for Identity (Preview)

Custom account correlation rules allow you to correlateare a Microsoft Defender for Identity setting for accounts that don't share strong identifiers. These identifiers such asinclude account ID, SID, object ID, or UPN. This isThe rules are especially useful for privileged accounts with unique naming conventions. By defining custom policies,rules, you get full visibility and better protection for all accounts.

:::image type="content" source="media/account-correlation-rules-settings.png" alt-text="Screenshot of the Account Correlation Rules settings page with rule management actions and configured rules." lightbox="media/account-correlation-rules-settings.png":::

Before you begin, review the license and role requirements in Prerequisites.

This article explains how to choose a correlation type, create custom account correlation rules, and edit or remove existing rules in the Microsoft Defender portal.

Prerequisites

  • An active Microsoft Defender for Identity (MDI) license, or another license that includes MDIDefender for Identity (such as E5). Without the required license, the policies page is read-only.
  • At least one of the following roles to view policies:
    • Microsoft Entra ID roles: Security Reader, Security Operator, or Security Administrator
    • Defender roles: Security operations, Security data, Alerts (manage)

Add a correlation rule

To add an account correlation rule, follow these steps:

  1. In the Microsoft Defender portal at Microsoft Defender portal, go to Settings > Identities.
  2. Select Account Correlation Rules.
  3. Select Add Rule.
  4. In the wizard, enter a Rule Name (up to 50 characters). You can use letters, numbers, and the following special characters: . - _ ! # ^ ~.

Edit a correlation rule

To change an existing account correlation rule, follow these steps:

  1. On the Account Correlation Rules page, select the checkbox next to the rule you want to edit. You can select only one rule at a time.
  2. Select Edit.
  3. In the wizard, update the rule configuration as needed.

Remove a correlation rule

To remove an account correlation rule, follow these steps:

  1. On the Account Correlation Rules page, select the checkbox next to the rule you want to remove.
  2. Select Delete.
  3. In the confirmation prompt, select Remove to confirm, or Cancel to abort. Correlation rule changes take effect within 12 hours.