Microsoft Defender XDR
Identity protection

View your identity coverage and maturity (Preview)

In brief

The page now explains coverage task ranking fields, observed-application filtering, and the On-premises identities panel, including sensor onboarding, activation, migration metrics, and related actions. SaaS panel guidance was also updated.

What Defender admins need to know

Administrators can use the expanded descriptions to interpret coverage priorities and track on-premises sensor onboarding and migration status.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review top setup tasks to improve coverage

The Top setup tasks section shows up to five cards at the top of the page representing the most important things you can do to improve your coverage. Each card shows the task name, source type (such as Identity provider or SaaS), and two ranking fields: impact level,(the security benefit of completing the task) and estimated effort (the work required to complete it).

Tasks are ranked so that high-impact, low-effort items appear first:

  1. On-premises sensor deployment, Microsoft Entra ID connector, and app governance
  2. SaaS app connectors
    Column Description
    Action name The setup task, such as connecting a specific app, sensor, or partner solution.
    ObservedWhether the application or integration is detected in your environment. This column isn't available in the On-premises identities side panel.
    Impact The security impact of completing the action.
    Effort The estimated effort to complete the action.

SaaS identities panel

The SaaS identities panel includes additional options that aren't available for other coverage sources:

  • An Observed column that indicates whether each application is detected in your environment.
  • AMost side panels include a Show Only Observed Applications toggle. By default, only observed applications and integrations are shown. Turn off the toggle to also see other supported SaaS appsapplications and integrations that aren't currently observed.

On-premises identities panel

The On-premises identities panel shows sensor onboarding and migration progress for discovered servers.

:::image type="content" source="media/on-premises-identities-side-panel.png" alt-text="Screenshot that shows the On-premises identities side panel in Microsoft Defender." lightbox="media/on-premises-identities-side-panel.png":::

The panel includes the following metrics:

MetricDescription
Onboarded manuallyServers that are onboarded with sensor version 2.
ActivatedServers ready for one-click sensor version 3 activation.
MigratedSensors running version 2 that are eligible to move to sensor version 3.

The Coverage progress list can include the following action names:

Action nameDescription
Activate V3Servers ready for one-click sensor version 3 activation.
Onboarding manuallyServers that aren't eligible for activation and should be onboarded with sensor version 2.
MigrationSensors running version 2 that are eligible to move to sensor version 3.

SaaS identities panel

The SaaS identities panel shows observed SaaS applications and other supported SaaS apps that you can connect.

:::image type="content" source="media/saas-identities-side-panel.png" alt-text="Screenshot that shows the SaaS identities side panel with the Observed column and Show Only Observed Applications toggle in Microsoft Defender." lightbox="media/saas-identities-side-panel.png":::