Microsoft Defender for Identity
Identity protection

Daily Operational Guide - Microsoft Defender for Identity

In brief

The guide’s title and metadata were updated, and its incident-triage guidance was streamlined. It continues to recommend reviewing the Global and Sensor Health Issues tabs and setting up service-issue email notifications.

What Defender admins need to know

Administrators have clearer guidance for monitoring deployment health and receiving service alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Daily operational guide - Microsoft Defender for Identity

Persona: SOC analysts

When triaging incidents:incidents:

  1. In the incident dashboard, filter for the following items:

  2. When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification.

Configure tuning rules for benign true positives / false positive alerts

Where: In Microsoft Defender, select Hunting > Advanced hunting

Persona: Security administrators, Active Directory administrators

We recommend checkingCheck the Health Issues page regularly to check for any problems in your Defender for Identity deployment, such as connectivity or sensor issues. Make sure to checkReview both the Global and Sensor tabs to view both types of issues.tabs.

We also recommend setting up email notifications for service issues so thatissues. Notifications help you can catch issuesproblems as they happen.

For more information, see Microsoft Defender for Identity health issues and Configure email notifications.

Related content

For more information, see: