Weekly Operational Guide - Microsoft Defender for Identity
In brief
The page title, publication date, and custom metadata were updated. Wording about configuring and running custom detection rules was streamlined, including how they trigger alerts and response actions.
What Defender admins need to know
Use the updated guide when reviewing custom detection guidance. No administrator action is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Weekly operational guide - Microsoft Defender for Identity
Persona: Security and compliance administrators, SOC analysts
We recommend that you configureConfigure custom detections in Microsoft Defender to monitor and respond to various events and system states, such aslike suspected breach activity and misconfigured endpoints.
Custom detection rules use advanced hunting queries. They can trigger alerts and response actions automatically.on their own. Run these rules regularly to stay on top of new alerts and take action.
For more information, see:
Related content
For more information, see:
@@ -1,11 +1,11 @@ ----title: Weekly operational guide - Microsoft Defender for Identity+title: Weekly Operational Guide - Microsoft Defender for Identity description: Learn about the Microsoft Defender for Identity activities that we recommend for your team on a weekly basis.-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.topic: how-to ms.reviewer: martin77s ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Weekly operational guide - Microsoft Defender for Identity@@ -33,9 +33,9 @@ For more information, see: **Persona**: Security and compliance administrators, SOC analysts -We recommend that you configure custom detections in Microsoft Defender to monitor and respond to various events and system states, such as suspected breach activity and misconfigured endpoints.+Configure custom detections in Microsoft Defender to monitor and respond to events like suspected breach activity and misconfigured endpoints. -Custom detection rules use advanced hunting queries. They can trigger alerts and response actions automatically. Run these rules regularly to stay on top of new alerts and take action.+Custom detection rules use advanced hunting queries. They can trigger alerts and response actions on their own. Run these rules regularly to stay on top of new alerts and take action. For more information, see: @@ -60,8 +60,6 @@ For more information, see [Proactively hunt for threats with advanced hunting in ## Related content -For more information, see:- - [Microsoft Defender Security operations overview](/security/operations/overview) - [Microsoft Defender for Identity operational guide](ops-guide.md) - [Daily operational guide - Microsoft Defender for Identity](ops-guide-daily.md) 