Microsoft Defender for Identity
Identity protection

Entity tags in Microsoft Defender for Identity

In brief

The article now uses Microsoft Defender terminology, clarifies sensitive, Exchange server, and honeytoken tagging guidance, and notes that Entra ID and SailPoint Identity Security Cloud roles are used for sensitive entity tagging.

What Defender admins need to know

Administrators managing entity tags can use the updated terminology and role guidance. No required action or deadline is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Defender for Identity entity tags in Microsoft Defender XDR

This article describes how to apply entity tags in Microsoft Defender for Identity entity tags, forIdentity. You can tag accounts as sensitive, as Exchange server,servers, or honeytoken accounts.as honeytokens.

  • You must tagTag sensitive accounts forso that detections work correctly. Some detections, like sensitive group changes, rely on this tag.

    Defender for Identity detections that rely on an entity's sensitivity status, for example, sensitive group modification detections.

    While Defender for Identity automatically tags Exchange servers as high-value, sensitive assets, youby default. You can also manually tag devices as Exchange servers.servers manually.

  • Tag honeytoken accounts to set traps for malicious actors. Since honeytokenThese accounts are usually dormant, any authentication associated withdormant. Any sign-in from a honeytoken account triggers an alert.

Prerequisites

To set Defender for Identity entity tags in Microsoft Defender XDR,Defender, you'll need Defender for Identity deployed in your environment, and administrator or user access to Microsoft Defender XDR.Defender.

For more information, see Microsoft Defender for Identity role groups.

SailPoint Identity Security Cloud sensitive roles

The following Entra ID and SailPoint Identity Security Cloud roles are used for sensitive entity tagging in Defender for Identity.

Entra ID roles used for tagging

Related content

For more information, see Investigate Defender for Identity security alerts in Microsoft Defender.