Remediation Actions for Compromised Users in Microsoft Defender for Identity
In brief
The article now explains that remediation actions depend on the connector managing an identity and includes connected apps through Microsoft Defender for Cloud Apps. Enable is listed for CyberArk Identity, SailPoint Identity Security Cloud, and Salesforce, while Force password change is listed for Microsoft Entra ID as well as Active Directory.
What Defender admins need to know
Use the updated support matrix to confirm which remediation actions are available for each connected identity source before responding to compromised accounts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Microsoft Defender for Identity
- Microsoft Defender
Microsoft Defender for Identity allowslets you to respond to compromised users by disabling their accounts or resetting their password. After taking action on users, you can checkwith remediation actions that work consistently across your connected identity sources. The actions available for an identity depend on the activity details inconnector that manages the action center.account, and they span on-premises Active Directory and Microsoft Entra ID, identity providers such as Okta, CyberArk Identity, and SailPoint Identity Security Cloud, and applications connected through Microsoft Defender for Cloud Apps such as Google Workspace, Salesforce, and Box.
The response actions on users are available directly from the useridentity page, the useridentity side panel, the advanced hunting page, or in the action center. After you take action on a user, you can review the activity details in the action center.
How remediation actions work
After authorization, the action is executed by the identity system that manages the affected account:
- Active Directory: Actions are executed by the Microsoft Defender for Identity sensor on the domain controller. Only sensors installed on domain controllers perform remediation actions; sensors on AD FS, AD CS, or Microsoft Entra Connect servers don't perform remediation actions. The sensor uses the domain controller's local system account to perform the action.
Microsoft Entra ID: Microsoft Defender for Identity creates and uses a Microsoft‑managed enterprise application to execute remediation actions in Entra ID.
- Application name: Microsoft Defender for Identity. In older tenants, the application might appear with the name Radius Aad Syncer.
- Application ID:
60ca1954-583c-4d1f-86de-39d835f3e452
Supported non‑Microsoft identity
providers (IdPs)sources and connected apps: Actions are executedusingthrough the sourceIdP’'sAPIs based onconnector, including identity provider connectors and Microsoft Defender for Cloud Apps app connectors, using the credentials configured for the integration.
Remediation actions are recorded by the identity system where the action is executed and are visible in Microsoft Defender audit logs.
Depending on your Microsoft Entra ID roles, you might see additional Microsoft Entra ID actions, such as requiring users to sign in again and confirming a user as compromised. For more information, see Remediate risks and unblock users.
| Remediation |
Description | Supported |
|---|---|---|
| Disable | Disables all accounts linked to an identity or a specific account. Disabling prevents sign-in and access to network resources until the accounts are re-enabled. This action doesn't delete the identity profile or associated data such as documents, calendar events, or email messages. |
|
| Enable | Re-enables accounts that were previously disabled for the selected identity. |
|
| Revoke session | Revokes active sessions for the selected identity. |
|
| Mark as compromised | Marks all accounts linked to the selected identity as compromised in Microsoft Entra ID. | Microsoft Entra ID |
| Force password change | Forces a password change for one or more accounts linked to the selected identity. The user must change their password at next sign-in, which prevents further use of compromised credentials. | Active |
Roles and permissions
The following table lists the remediation actions supported by Defender for Identity and the roles required to initiate each action.
| Remediation Action | Active Directory | Microsoft Entra ID | Supported SaaS apps | |
|---|---|---|---|---|
| Disable | See Required permissions Defender for Identity in Microsoft Defender XDR |
|
Global Administrator, Security |
|
| Enable | See Required permissions Defender for Identity in Microsoft Defender XDR |
|
Global Administrator, Security |
|
| Revoke session | N/A |
|
| N/A |
| Mark as compromised | N/A |
| N/A | N/A |
| Force password change | See Required permissions Defender for Identity in Microsoft Defender XDR | |||
| N/A | N/A |
| ||
|
To perform any of the supported actions, you need to:
- Configure the account that Microsoft Defender for Identity uses to perform
actions.actions: Make sure the Automatically use the sensor's local system account option is selected. In the Microsoft Defender portal, go to Settings > Identities > Microsoft Defender for Identity > Manage action accounts. This setting is required if any of your sensors are v3.x. For more information, see Manage action accounts. - Sign in to the Microsoft Defender portal with the required
permissions.permissions: For Defender for Identity actions, you'll need a custom role with Response (manage) permissions. For more information, see Create custom roles with Microsoft Defender unified RBAC. For details on the specific roles required for each action, see Roles and permissions.
To apply a remediation action to an identity, perform the following steps:
In the Microsoft Defender portal, go to one of the following locations:
- Identity page: Go to Assets > Identities
,and select the identity you want to act on. - Advanced hunting page: Go to Hunting > Advanced hunting
,and identify a result that includes an identity entity. - Action center: Go to Actions & submissions > Action center to review and manage pending or completed actions.
- Identity page: Go to Assets > Identities
Select Actions or right-click the identity to open the actions menu.
The action is submitted and executed by the relevant identity system. You can track the status in the Action center.
Video: Defender for Identity remediation actionsRelated content
Remediation actions in Microsoft Defender for IdentityNew Remediation actions in Microsoft Defender for Identity (video)- Configure Microsoft Defender for Identity action accounts
See also
@@ -1,9 +1,9 @@ ----title: Remediation actions for compromised users in Microsoft Defender for Identity+title: Remediation Actions for Compromised Users in Microsoft Defender for Identity description: Learn how to respond to compromised users with remediation actions in Microsoft Defender for Identity-ms.date: 06/15/2026+ms.date: 07/22/2026 ms.topic: how-to-ms.custom: sfi-ga-blocked, msecd-doc-authoring-1014+ms.custom: sfi-ga-blocked, msecd-doc-authoring-1016 ai-usage: ai-assisted --- @@ -14,9 +14,9 @@ Applies to: - Microsoft Defender for Identity - Microsoft Defender -Microsoft Defender for Identity allows you to respond to compromised users by disabling their accounts or resetting their password. After taking action on users, you can check on the activity details in the action center.+Microsoft Defender for Identity lets you respond to compromised users with remediation actions that work consistently across your connected identity sources. The actions available for an identity depend on the connector that manages the account, and they span on-premises Active Directory and Microsoft Entra ID, identity providers such as Okta, CyberArk Identity, and SailPoint Identity Security Cloud, and applications connected through Microsoft Defender for Cloud Apps such as Google Workspace, Salesforce, and Box. -The response actions on users are available directly from the user page, the user side panel, the advanced hunting page, or in the action center.+The response actions on users are available directly from the identity page, the identity side panel, the advanced hunting page, or in the action center. After you take action on a user, you can review the activity details in the action center. ## How remediation actions work @@ -24,19 +24,16 @@ Remediation actions are initiated by a user in the Microsoft Defender portal and After authorization, the action is executed by the identity system that manages the affected account: -- **Active Directory**- Actions are executed by the Microsoft Defender for Identity sensor on the domain controller. Only sensors installed on domain controllers perform remediation actions; sensors on AD FS, AD CS, or Microsoft Entra Connect servers don't perform remediation actions. The sensor uses the domain controller's local system account to perform the action.+- **Active Directory**: Actions are executed by the Microsoft Defender for Identity sensor on the domain controller. Only sensors installed on domain controllers perform remediation actions; sensors on AD FS, AD CS, or Microsoft Entra Connect servers don't perform remediation actions. The sensor uses the domain controller's local system account to perform the action. > [!IMPORTANT] > Make sure the **Automatically use the sensor's local system account** option is selected. This is required for sensor v3.x and recommended for all environments, including mixed (v2.x and v3.x) deployments. To verify, in the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Identities** > **Microsoft Defender for Identity** > **Manage action accounts**. -- **Microsoft Entra ID**- Microsoft Defender for Identity creates and uses a Microsoft‑managed enterprise application to execute remediation actions in Entra ID. +- **Microsoft Entra ID**: Microsoft Defender for Identity creates and uses a Microsoft‑managed enterprise application to execute remediation actions in Entra ID. - **Application name:** *Microsoft Defender for Identity*. In older tenants, the application might appear with the name *Radius Aad Syncer*. - **Application ID:** `60ca1954-583c-4d1f-86de-39d835f3e452` -- **Supported non‑Microsoft identity providers (IdPs)**- Actions are executed using the source IdP’s APIs based on the credentials configured for the integration.+- **Supported non‑Microsoft identity sources and connected apps**: Actions are executed through the source's connector, including identity provider connectors and Microsoft Defender for Cloud Apps app connectors, using the credentials configured for the integration. Remediation actions are recorded by the identity system where the action is executed and are visible in Microsoft Defender audit logs. @@ -50,29 +47,25 @@ The following Defender for Identity actions can be performed on Identities. Depending on your Microsoft Entra ID roles, you might see additional Microsoft Entra ID actions, such as requiring users to sign in again and confirming a user as compromised. For more information, see [Remediate risks and unblock users](/entra/id-protection/howto-identity-protection-remediate-unblock). -| Remediation Action | Description | Supported Identity systems |+| Remediation action | Description | Supported identity sources | | ------------------ | ----------- | ------ |-| Disable | Disables all accounts linked to an identity or a specific account. Disabling prevents sign-in and access to network resources until the accounts are re-enabled. This action doesn't delete the identity profile or associated data such as documents, calendar events, or email messages. | <ul><li>Active Directory</li><li>Microsoft Entra ID</li><li>Okta</li></ul> |-| Enable | Re-enables accounts that were previously disabled for the selected identity. | <ul><li>Active Directory</li><li>Microsoft Entra ID</li><li>Okta</li></ul> |-| Revoke session | Revokes active sessions for the selected identity. | <ul><li>Microsoft Entra ID</li><li>Okta</li></ul> |+| Disable | Disables all accounts linked to an identity or a specific account. Disabling prevents sign-in and access to network resources until the accounts are re-enabled. This action doesn't delete the identity profile or associated data such as documents, calendar events, or email messages. | Active Directory, Microsoft Entra ID, Okta, CyberArk Identity, SailPoint Identity Security Cloud, Google Workspace, Salesforce, Box |+| Enable | Re-enables accounts that were previously disabled for the selected identity. | Active Directory, Microsoft Entra ID, Okta, CyberArk Identity, SailPoint Identity Security Cloud, Salesforce |+| Revoke session | Revokes active sessions for the selected identity. | Microsoft Entra ID, Okta | | Mark as compromised | Marks all accounts linked to the selected identity as compromised in Microsoft Entra ID. | Microsoft Entra ID |-| Force password change | Forces a password change for one or more accounts linked to the selected identity. The user must change their password at next sign-in, which prevents further use of compromised credentials. | Active Directory |-| Deactivate | Permanently deactivates a non-legitimate malicious account. | Okta |-| Set account risk to High/Medium/Low | Sets account risk scoring to one of the defined levels. Available only when the [Risk Scoring](https://help.okta.com/en-us/Content/Topics/Security/Security_Risk_Scoring.htm) feature is enabled in Okta. | Okta |+| Force password change | Forces a password change for one or more accounts linked to the selected identity. The user must change their password at next sign-in, which prevents further use of compromised credentials. | Active Directory, Microsoft Entra ID | ## Roles and permissions The following table lists the remediation actions supported by Defender for Identity and the roles required to initiate each action. -| Remediation Action | Active Directory |Microsoft Entra ID | Okta |-| ---- | ---- | ---- | ---- |-| Disable | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | <ul><li>Global Administrator</li><li>User Administrator</li><li>Authentication Administrator</li><li>Privileged Authentication Administrator</li><li>Directory Writers</li></ul> | <ul><li>Security Operator</li><li>Security Administrator</li><li>Global Administrator</li></ul> |-| Enable | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) |<ul><li>Global Administrator</li><li>User Administrator</li><li>Authentication Administrator</li><li>Privileged Authentication Administrator</li><li>Directory Writers</li></ul> |<ul><li>Security Operator</li><li>Security Administrator</li><li>Global Administrator</li></ul> |-| Revoke session | N/A |<ul><li>Global Administrator</li><li>User Administrator</li><li>Authentication Administrator</li><li>Privileged Authentication Administrator</li><li>Directory Writers</li><li>Helpdesk Administrator</li></ul> |<ul><li>Security Operator</li><li>Security Administrator</li><li>Global Administrator</li></ul> |-| Mark as compromised | N/A |<ul><li>Global Administrator</li><li>Security Administrator</li><li>Security Operator</li></ul> | N/A |-| Force password change | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | N/A | N/A |-| Deactivate | N/A | N/A |<ul><li>Security Operator</li><li>Security Administrator</li><li>Global Administrator</li></ul> |-| Set identity risk to High/Medium/Low | N/A | N/A |<ul><li>Security Operator</li><li>Security Administrator</li><li>Global Administrator</li></ul> |+| Remediation Action | Active Directory | Microsoft Entra ID | Okta, SailPoint, CyberArk | Supported SaaS apps |+| ---- | ---- | ---- | ---- | ---- |+| Disable | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | Global Administrator, User Administrator, Authentication Administrator, Privileged Authentication Administrator, Directory Writers, SOC Identity Responder | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | Global Administrator, Security Administrator, Cloud App Security Administrator |+| Enable | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | Global Administrator, User Administrator, Authentication Administrator, Privileged Authentication Administrator, Directory Writers | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | Global Administrator, Security Administrator, Cloud App Security Administrator |+| Revoke session | N/A | Global Administrator, User Administrator, Authentication Administrator, Privileged Authentication Administrator, Directory Writers, Helpdesk Administrator, SOC Identity Responder | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | N/A |+| Mark as compromised | N/A | Global Administrator, Security Administrator, Security Operator, SOC Identity Responder | N/A | N/A |+| Force password change | See [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr) | Global Administrator, Privileged Authentication Administrator, Authentication Administrator, User Administrator, Password Administrator, Helpdesk Administrator, SOC Identity Responder | N/A | N/A | > [!NOTE] > There are some limitations for Microsoft Entra ID when performing certain actions on other roles. For more information, see the [Graph API documentation](/graph/api/resources/users?view=graph-rest-1.0&preserve-view=true).@@ -81,14 +74,14 @@ The following table lists the remediation actions supported by Defender for Iden To perform any of the [supported actions](#supported-actions), you need to: -- **Configure the account that Microsoft Defender for Identity uses to perform actions.** Make sure the **Automatically use the sensor's local system account** option is selected. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Identities** > **Microsoft Defender for Identity** > **Manage action accounts**. This setting is required if any of your sensors are v3.x. For more information, see [Manage action accounts](deploy/manage-action-accounts.md).-- **Sign in to the Microsoft Defender portal with the required permissions.** For Defender for Identity actions, you'll need a custom role with **Response (manage)** permissions. For more information, see [Create custom roles with Microsoft Defender unified RBAC](/microsoft-365/security/defender/create-custom-rbac-roles). For details on the specific roles required for each action, see [Roles and permissions](#roles-and-permissions).+- **Configure the account that Microsoft Defender for Identity uses to perform actions**: Make sure the **Automatically use the sensor's local system account** option is selected. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Identities** > **Microsoft Defender for Identity** > **Manage action accounts**. This setting is required if any of your sensors are v3.x. For more information, see [Manage action accounts](deploy/manage-action-accounts.md).+- **Sign in to the Microsoft Defender portal with the required permissions**: For Defender for Identity actions, you'll need a custom role with **Response (manage)** permissions. For more information, see [Create custom roles with Microsoft Defender unified RBAC](/microsoft-365/security/defender/create-custom-rbac-roles). For details on the specific roles required for each action, see [Roles and permissions](#roles-and-permissions). To apply a remediation action to an identity, perform the following steps: 1. In the [Microsoft Defender portal](https://security.microsoft.com), go to one of the following locations:- - **Identity page**: Go to **Assets** > **Identities**, and select the identity you want to act on.- - **Advanced hunting page**: Go to **Hunting** > **Advanced hunting**, and identify a result that includes an identity entity.+ - **Identity page**: Go to **Assets** > **Identities** and select the identity you want to act on.+ - **Advanced hunting page**: Go to **Hunting** > **Advanced hunting** and identify a result that includes an identity entity. - **Action center**: Go to **Actions & submissions** > **Action center** to review and manage pending or completed actions. 1. Select **Actions** or right-click the identity to open the actions menu.@@ -99,11 +92,7 @@ To apply a remediation action to an identity, perform the following steps: The action is submitted and executed by the relevant identity system. You can track the status in the **Action center**. -<a name="related-video"></a>-## Video: Defender for Identity remediation actions+## Related content -- [Remediation actions in Microsoft Defender for Identity](https://learn-video.azurefd.net/vod/id/adc6068b-225c-457d-b053-db6b64dedb79)--## See also--[Microsoft Defender for Identity action accounts](deploy/manage-action-accounts.md)+- [New Remediation actions in Microsoft Defender for Identity (video)](https://www.youtube.com/watch?v=qDvmI-Y3cKY)+- [Configure Microsoft Defender for Identity action accounts](deploy/manage-action-accounts.md) 