Microsoft Defender for Identity
Identity protection

Remediation Actions for Compromised Users in Microsoft Defender for Identity

In brief

The article now explains that remediation actions depend on the connector managing an identity and includes connected apps through Microsoft Defender for Cloud Apps. Enable is listed for CyberArk Identity, SailPoint Identity Security Cloud, and Salesforce, while Force password change is listed for Microsoft Entra ID as well as Active Directory.

What Defender admins need to know

Use the updated support matrix to confirm which remediation actions are available for each connected identity source before responding to compromised accounts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Microsoft Defender for Identity
  • Microsoft Defender

Microsoft Defender for Identity allowslets you to respond to compromised users by disabling their accounts or resetting their password. After taking action on users, you can checkwith remediation actions that work consistently across your connected identity sources. The actions available for an identity depend on the activity details inconnector that manages the action center.account, and they span on-premises Active Directory and Microsoft Entra ID, identity providers such as Okta, CyberArk Identity, and SailPoint Identity Security Cloud, and applications connected through Microsoft Defender for Cloud Apps such as Google Workspace, Salesforce, and Box.

The response actions on users are available directly from the useridentity page, the useridentity side panel, the advanced hunting page, or in the action center. After you take action on a user, you can review the activity details in the action center.

How remediation actions work

After authorization, the action is executed by the identity system that manages the affected account:

  • Active Directory: Actions are executed by the Microsoft Defender for Identity sensor on the domain controller. Only sensors installed on domain controllers perform remediation actions; sensors on AD FS, AD CS, or Microsoft Entra Connect servers don't perform remediation actions. The sensor uses the domain controller's local system account to perform the action.
  • Microsoft Entra ID: Microsoft Defender for Identity creates and uses a Microsoft‑managed enterprise application to execute remediation actions in Entra ID.

    • Application name: Microsoft Defender for Identity. In older tenants, the application might appear with the name Radius Aad Syncer.
    • Application ID: 60ca1954-583c-4d1f-86de-39d835f3e452
  • Supported non‑Microsoft identity providers (IdPs)sources and connected apps: Actions are executed usingthrough the source IdP’'s APIs based onconnector, including identity provider connectors and Microsoft Defender for Cloud Apps app connectors, using the credentials configured for the integration.

Remediation actions are recorded by the identity system where the action is executed and are visible in Microsoft Defender audit logs.

Depending on your Microsoft Entra ID roles, you might see additional Microsoft Entra ID actions, such as requiring users to sign in again and confirming a user as compromised. For more information, see Remediate risks and unblock users.

Remediation Actionaction Description Supported Identity systemsidentity sources
Disable Disables all accounts linked to an identity or a specific account. Disabling prevents sign-in and access to network resources until the accounts are re-enabled. This action doesn't delete the identity profile or associated data such as documents, calendar events, or email messages.
  • Active Directory
  • Directory, Microsoft Entra ID
  • Okta
ID, Okta, CyberArk Identity, SailPoint Identity Security Cloud, Google Workspace, Salesforce, Box
Enable Re-enables accounts that were previously disabled for the selected identity.
  • Active Directory
  • Directory, Microsoft Entra ID
  • Okta
ID, Okta, CyberArk Identity, SailPoint Identity Security Cloud, Salesforce
Revoke session Revokes active sessions for the selected identity.
  • Microsoft Entra ID
  • ID, Okta
Mark as compromised Marks all accounts linked to the selected identity as compromised in Microsoft Entra ID. Microsoft Entra ID
Force password change Forces a password change for one or more accounts linked to the selected identity. The user must change their password at next sign-in, which prevents further use of compromised credentials. Active Directory
DeactivatePermanently deactivates a non-legitimate malicious account.Okta
Set account risk to High/Medium/LowSets account risk scoring to one of the defined levels. Available only when the Risk Scoring feature is enabled in Okta.OktaDirectory, Microsoft Entra ID

Roles and permissions

The following table lists the remediation actions supported by Defender for Identity and the roles required to initiate each action.

Remediation Action Active Directory Microsoft Entra ID OktaOkta, SailPoint, CyberArkSupported SaaS apps
Disable See Required permissions Defender for Identity in Microsoft Defender XDR
  • Global Administrator
  • Administrator, User Administrator
  • Administrator, Authentication Administrator
  • Administrator, Privileged Authentication Administrator
  • Administrator, Directory Writers
Writers, SOC Identity Responder
Global Administrator, Security Operator
  • Administrator, Cloud App Security Administrator
  • Global Administrator
  • Enable See Required permissions Defender for Identity in Microsoft Defender XDR
    • Global Administrator
    • Administrator, User Administrator
    • Administrator, Authentication Administrator
    • Administrator, Privileged Authentication Administrator
    • Administrator, Directory Writers
    Global Administrator, Security Operator
  • Administrator, Cloud App Security Administrator
  • Global Administrator
  • Revoke session N/A
    • Global Administrator
    • Administrator, User Administrator
    • Administrator, Authentication Administrator
    • Administrator, Privileged Authentication Administrator
    • Administrator, Directory Writers
    • Writers, Helpdesk Administrator
    Administrator, SOC Identity Responder
    • Security Operator
    • Security Administrator
    • Global Administrator
    See Required permissions Defender for Identity in Microsoft Defender XDR
    N/A
    Mark as compromised N/A
    • Global Administrator
    • Administrator, Security Administrator
    • Administrator, Security Operator
    Operator, SOC Identity Responder
    N/A N/A
    Force password change See Required permissions Defender for Identity in Microsoft Defender XDR N/AN/A
    DeactivateGlobal Administrator, Privileged Authentication Administrator, Authentication Administrator, User Administrator, Password Administrator, Helpdesk Administrator, SOC Identity Responder N/A N/A
    • Security Operator
    • Security Administrator
    • Global Administrator
    Set identity risk to High/Medium/LowN/AN/A
    • Security Operator
    • Security Administrator
    • Global Administrator

    To perform any of the supported actions, you need to:

    • Configure the account that Microsoft Defender for Identity uses to perform actions.actions: Make sure the Automatically use the sensor's local system account option is selected. In the Microsoft Defender portal, go to Settings > Identities > Microsoft Defender for Identity > Manage action accounts. This setting is required if any of your sensors are v3.x. For more information, see Manage action accounts.
    • Sign in to the Microsoft Defender portal with the required permissions.permissions: For Defender for Identity actions, you'll need a custom role with Response (manage) permissions. For more information, see Create custom roles with Microsoft Defender unified RBAC. For details on the specific roles required for each action, see Roles and permissions.

    To apply a remediation action to an identity, perform the following steps:

    1. In the Microsoft Defender portal, go to one of the following locations:

      • Identity page: Go to Assets > Identities, and select the identity you want to act on.
      • Advanced hunting page: Go to Hunting > Advanced hunting, and identify a result that includes an identity entity.
      • Action center: Go to Actions & submissions > Action center to review and manage pending or completed actions.
    2. Select Actions or right-click the identity to open the actions menu.

    The action is submitted and executed by the relevant identity system. You can track the status in the Action center.

    Video: Defender for Identity remediation actionsRelated content

    See also

    Microsoft Defender for Identity action accounts