Microsoft Defender XDR
Identity protection

Manage predictive shielding in Microsoft Defender

In brief

The page now highlights Defender for Identity data enrichment, advanced hunting for policy changes, and undoing shielding actions. It also clarifies alert investigation steps and refines the example scenario.

What Defender admins need to know

No action is required; administrators can use the clearer guidance when managing predictive shielding.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage predictive shielding in Microsoft Defender (Preview)

Review the triggering alert information

To investigate the alert that triggered a specific predictive shielding action, select that action'sthe triggering alert for the action you are investigating, either from the incident details pane or from the activity page.

:::image type="content" source="media/shield-predict-threats-manage/shield-predict-threats-view-triggering-alert.png" alt-text="Screenshot of the alert details pane showing relevant alert data." lightbox="media/shield-predict-threats-manage/shield-predict-threats-view-triggering-alert.png":::

Enriched data example

In the following scenario:This example scenario shows how enriched data enhances predictive shielding:

  • Both Microsoft Defender for Endpoint and Microsoft Defender for Identity are enabled in the environment.
  • An attacker gained a foothold on a jump box and conducted malicious activities that led to compromising a workstation (WSA).named WSA.
  • The enriched data reveals suspicious PowerShell activities on WSA, indicating the attacker's intent to perform remote credential harvesting on another workstation, WSB.
  • This enrichment adds predictive data on the incident, and indicates intent for further compromise.

:::image type="content" source="media/shield-predict-threats-manage/shield-predict-threats-enriched-data.png" alt-text="Screenshot of enriched predictive shielding data in an incident, showing user and Active Directory details.":::