Microsoft Defender XDR
Hunting and detection

Advanced Hunting Extend Data

In brief

The page wording was revised to emphasize correct settings across data sources, and section headings now clearly describe enabling Windows advanced security auditing and installing the Defender for Identity sensor. Section anchors and the page date were also updated.

What Defender admins need to know

Administrators can use the clearer headings and guidance when configuring data sources for advanced hunting.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Microsoft Defender XDR rebranding]

Configure data sources for advanced hunting

Advanced hunting relies on data coming from various sources, includingsources. These sources include your devices, your Office 365 workspaces, Microsoft Entra ID, and Microsoft Defender for Identity. To get the most comprehensive data possible, ensure thatcomplete data, make sure you have the correct settings in the correspondingeach data sources.source.

AdvancedEnable advanced security auditing on Windows devices

Turn on these advanced auditing settings to ensure you get data about activities on your devices, including local account management, local security group management, and service creation.

| Data | Description | Schema table | How to configure | | Security group management | Events captured as various ActionType values indicating local security group creation and other local group management activities | DeviceEvents | - Deploy an advanced security audit policy: Audit Security Group Management
- Learn about advanced security audit policies | | Service installation | Events captured with the ActionType value ServiceInstalled, indicating that a service has been created | DeviceEvents | - Deploy an advanced security audit policy: Audit Security System Extension
- Learn about advanced security audit policies |

Install the Microsoft Defender for Identity sensor on the domain controller

If you're running Active Directory on premises, you need to install the Microsoft Defender for Identity sensor on the domain controller to get data for Microsoft Defender for Identity. When installed and properly configured, data from on-premises Active Directory also feeds into advanced hunting through Microsoft Defender for Identity and provides a more holistic picture of identity information and events in your network. Data collected by the Defender for Identity sensor also enhances the ability of Microsoft Defender for Identity to generate relevant alerts that are also covered by advanced hunting.

| Data | Description | Schema table | How to configure |