Microsoft Sentinel
Developer and API

Normalization Schema Asset

In brief

The asset normalization schema now uses “Microsoft Entra” terminology instead of “Azure Active Directory” and updates the identity-directory example accordingly.

What Defender admins need to know

No administrator action is indicated; field names and requirements are unchanged.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Field Class Type Description
AADTenantId Mandatory string The Azure Active DirectoryMicrosoft Entra tenant identifier associated with the asset or entity.
IdentityDirectoryName Optional string The name of the identity directory, such as Azure AD,Microsoft Entra ID, GCP, or AWS, associated with the entity.
IdentityDirectoryId Mandatory string The identifier of the identity directory associated with the entity.
AdditionalFields Optional dynamic Additional information about the entity that is not captured by other fields in the schema.