Microsoft Defender for Identity
Identity protection

Weekly Operational Guide - Microsoft Defender for Identity

In brief

The page title, publication date, and custom metadata were updated. Wording about configuring and running custom detection rules was streamlined, including how they trigger alerts and response actions.

What Defender admins need to know

Use the updated guide when reviewing custom detection guidance. No administrator action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Weekly operational guide - Microsoft Defender for Identity

Persona: Security and compliance administrators, SOC analysts

We recommend that you configureConfigure custom detections in Microsoft Defender to monitor and respond to various events and system states, such aslike suspected breach activity and misconfigured endpoints.

Custom detection rules use advanced hunting queries. They can trigger alerts and response actions automatically.on their own. Run these rules regularly to stay on top of new alerts and take action.

For more information, see:

Related content

For more information, see: