Daily Operational Guide - Microsoft Defender for Identity
In brief
The guide’s title and metadata were updated, and its incident-triage guidance was streamlined. It continues to recommend reviewing the Global and Sensor Health Issues tabs and setting up service-issue email notifications.
What Defender admins need to know
Administrators have clearer guidance for monitoring deployment health and receiving service alerts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Daily operational guide - Microsoft Defender for Identity
Persona: SOC analysts
When triaging incidents:incidents:
In the incident dashboard, filter for the following items:
When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification.
Configure tuning rules for benign true positives / false positive alerts
Where: In Microsoft Defender, select Hunting > Advanced hunting
Persona: Security administrators, Active Directory administrators
We recommend checkingCheck the Health Issues page regularly to check for any problems in your Defender for Identity deployment, such as connectivity or sensor issues. Make sure to checkReview both the Global and Sensor tabs to view both types of issues.tabs.
We also recommend setting up email notifications for service issues so thatissues. Notifications help you can catch issuesproblems as they happen.
For more information, see Microsoft Defender for Identity health issues and Configure email notifications.
Related content
For more information, see:
@@ -1,11 +1,11 @@ ----title: Daily operational guide - Microsoft Defender for Identity+title: Daily Operational Guide - Microsoft Defender for Identity description: Learn about the Microsoft Defender for Identity activities that we recommend for your team on a daily basis.-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.topic: how-to ms.reviewer: martin77s ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Daily operational guide - Microsoft Defender for Identity@@ -28,7 +28,7 @@ For more information, see [Work with Defender for Identity's Identity Security d **Persona**: SOC analysts -**When triaging incidents**:+When triaging incidents: 1. In the incident dashboard, filter for the following items: @@ -54,7 +54,6 @@ For more information, see [Work with Defender for Identity's Identity Security d 1. When the incident is remediated, resolve it to resolve all linked and related active alerts and set a classification. - ## Configure tuning rules for benign true positives / false positive alerts **Where**: In Microsoft Defender, select **Hunting > Advanced hunting**@@ -89,16 +88,14 @@ For more information, see [Proactively hunt for threats with advanced hunting in **Persona**: Security administrators, Active Directory administrators -We recommend checking the **Health Issues** page regularly to check for any problems in your Defender for Identity deployment, such as connectivity or sensor issues. Make sure to check both the **Global** and **Sensor** tabs to view both types of issues.+Check the **Health Issues** page regularly for problems in your Defender for Identity deployment, such as connectivity or sensor issues. Review both the **Global** and **Sensor** tabs. -We also recommend setting up email notifications for service issues so that you can catch issues as they happen.+We also recommend setting up email notifications for service issues. Notifications help you catch problems as they happen. For more information, see [Microsoft Defender for Identity health issues](../health-alerts.md) and [Configure email notifications](../notifications.md#configure-email-notifications). ## Related content -For more information, see:- - [Microsoft Defender Security operations overview](/security/operations/overview) - [Microsoft Defender for Identity operational guide](ops-guide.md) - [Weekly operational guide - Microsoft Defender for Identity](ops-guide-weekly.md) 