A new page explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.
Today in Microsoft Defender
Every tracked change across Microsoft Defender documentation, in plain English. Browse the archive from 1 January 2026 → About this project →
Sentinel parser guidance forbids cross-table enrichment and preserves one output per source record
The day’s most consequential updates sharpen Sentinel parser guidance and revise the documented severity of seven Azure Storage alerts to Informational. Defender XDR added dedicated guidance for mapping Advanced Hunting results into graphs, while Defender for Identity added resolution steps for the Sensor v3.x RPC Audit Misconfigured health alert. The remaining edits are primarily layout, link, terminology, and explanatory maintenance.
- Sentinel parser guidance sets strict source and cardinality boundaries
Sentinel · Cloud and workloads
The updated normalization guidance limits parsers to the declared source table, requires one normalized output per source record, and permits scalar or local static mappings. It explicitly prohibits cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication. Source filtering must use fields in the current event; missing source information should be handled in the connector or source-specific table.
- Sentinel parser-creation guidance permits lookup mappings only with unique keys
Sentinel · Cloud and workloads
The parser-creation skills guidance says each source record is normalized independently and record cardinality is preserved. Query-local datatable or lookup mappings are allowed when lookup keys are unique, while same-table and cross-table event enrichment are not used.
- New Defender XDR guidance details graph mapping for Advanced Hunting
Defender XDR · Hunting and detection
The new guide explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.
- Azure Storage alert documentation now labels seven entries Informational
Defender for Cloud · Cloud and workloads
Seven documented Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants. Administrators reviewing the alert reference should use the revised labels when prioritizing those entries.
- Defender for Identity adds resolution steps for an RPC audit health alert
Identity · Identity protection
The health-issues article now includes resolution guidance for the Sensor v3.x RPC Audit Misconfigured entry, including verification of the Unified Sensor RPC Audit configuration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Defender XDR
2 updatesAdvanced Hunting Query Results
New featureAdvanced hunting results can be mapped to nodes and edges using a Builder or JSON, then explored with entity enrichment, relationship details, folding, and mapping edits.
Microsoft Defender for Endpoint
2 updatesLinux Preferences
Doc updateThe superscript asterisk was removed from the `nfs4` entry in the Linux preferences documentation.
Mde Linux Prerequisites
Doc updateThe filesystem entries on the Linux prerequisites page were redistributed between the two table columns; the listed entries remain unchanged.
Microsoft Defender for Identity
1 updateThe health alerts article revision date changed, and the Sensor v3.x RPC Audit Misconfigured entry now includes resolution guidance, including verifying the Unified Sensor RPC Audit configuration.
Working With The Regex Engine
Doc updateThe article now more clearly explains that it covers supported RegEx syntax, known limitations, and examples for building expressions in content inspection and file policies.
Microsoft Defender for Cloud
1 updateAlerts Azure Storage
Doc updateSeven Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants.
Microsoft Sentinel
3 updatesNormalization Develop Parsers
Feature updateThe documentation now restricts parsers to the declared source table, one normalized output per source record, and scalar or local static mappings. Cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication are prohibited for parser operations.
Normalization Create Parsers Ai Agent
Doc updateThe documentation now states that parser creation skills normalize each source record independently and preserve record cardinality. Query-local datatable/lookup mappings are allowed when lookup keys are unique, while same-table and cross-table event enrichment are not used.
Data Connector Ui Definitions Reference
Doc updateThe data connector UI definitions reference now uses the corrected relative link to the Create a codeless connector documentation.
