Microsoft Defender XDR: Unified response actions across identity accounts
In brief
Microsoft Defender XDR unifies identity response actions across linked accounts, enabling security teams to manage actions like disabling accounts or forcing password changes from one workflow. It supports multiple identity systems and SaaS apps, enhancing response speed and consistency. Rollout begins mid-October 2026 worldwide.
Message Center announcement
What and why:
Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts. Security teams will be able to apply supported response actions to all supported accounts associated with an identity, or to selected accounts, from a single workflow.
Available actions depend on the identity system or connector managing the account and may include:
- Disable account
- Enable account
- Revoke session
- Mark as compromised
- Force password change
Supported identity systems and applications include:
- Active Directory
- Microsoft Entra ID
- Okta
- CyberArk Identity
- SailPoint Identity Security Cloud
- Google Workspace
- Salesforce
- Box
This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications.
Rollout schedule:
- Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026.
Who is affected
- Security Operations Center (SOC) analysts
- Incident responders
- Identity administrators
- Administrators managing Microsoft Defender-connected identity systems
Platforms and services
- Microsoft Defender XDR
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Entra ID
- Supported third-party identity provider and SaaS application connectors
What will happen
- Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center.
- Available response actions vary based on the identity system or connector managing each account.
- Administrators can review action status in Action center and in audit records generated by the target system.
- No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action.
Action required / Recommendations:
No action is required to enable this capability. However, we recommend that administrators:
- Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles.
- Verify Microsoft Defender for Identity action account configuration for Active Directory response actions.
- If using Microsoft Defender for Identity sensor version 3.x, ensure the sensor is running under the Local System account.
- Verify that supported identity provider and SaaS application connectors are configured with credentials that allow the intended response actions.
- Enable Identity Inventory integration in Microsoft Defender for Cloud Apps if SaaS cloud accounts are included in response workflows.
- Update incident response runbooks and train analysts to verify selected accounts before confirming response actions.
Learn more
