Microsoft Defender XDR
General

Entity Page Device

In brief

The documentation clarifies that custom activity data from Microsoft Sentinel must include a strong identifier combination for the host to be mapped and displayed in the Device Timeline.

What Defender admins need to know

Administrators integrating Sentinel data can use the clarified guidance when validating host identifiers; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For more information about these activity events, see Entity pages in Microsoft Sentinel.

Strong identifier requirementsRequired strong identifiers for the unified timeline (Sentinel to XDR mapping)

To ensure that custom activity data (for example, Sophos alerts) from Microsoft Sentinel is correctly mapped and visible in Microsoft Defender XDR (security.microsoft.com) under the Device Timeline, the ingested data must include a strong identifier combination for the host.

Required strong identifiers

At a minimum, include one of the following strong identifier combinations: