← Previous week
Week in brief

Sentinel normalization guidance now prohibits cross-table enrichment and preserves record cardinality

The period’s most consequential update was revised Sentinel parser guidance: parsers are limited to their declared source table, one normalized output per source record, and scalar or local static mappings. Cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication are explicitly excluded. Companion AI-agent guidance permits query-local lookup mappings only when keys are unique. Defender XDR also added detailed advanced-hunting graph guidance, while seven Azure Storage alert entries now use Informational severity. Other changes were mainly editorial, with added troubleshooting steps for the Sensor v3.x RPC Audit Misconfigured alert.

  • The revised guidance limits parsers to the declared source table and one normalized output per source record, using scalar or local static mappings. It explicitly excludes cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication; source filtering must use fields from the current event.

  • Parser-creation skills are described as normalizing each source record independently while preserving record cardinality. Query-local datatable or lookup mappings are allowed only when lookup keys are unique; same-table and cross-table event enrichment are not used.

  • A new page explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.

  • The updated article documents mapping results to nodes and edges through Builder or JSON, then exploring entity enrichment, relationship details, folding, and mapping edits without writing a graph-specific query.

  • The documented severity for seven Azure Storage alerts changed from High, Medium, or Low variants to Informational. Administrators should use the revised labels when reviewing and prioritizing these documented alerts.

For Defender administrators

Review custom Sentinel parsers and connectors against the documented source-table, record-cardinality, and enrichment limits. For AI-agent parser creation, use unique lookup keys and plan for record-by-record normalization; no required configuration change is stated. Use the revised Informational labels when reviewing documented Azure Storage alerts. Administrators troubleshooting the Identity health alert should follow the added resolution guidance, including verification of Unified Sensor RPC Audit configuration. The Linux formatting, Regex scope, filesystem-layout, and connector-link edits require no action.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

2

Best practices for graph mapping in advanced hunting

Doc update

A new page explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.

8 September 2026

Advanced Hunting Query Results

New feature

Advanced hunting results can be mapped to nodes and edges using a Builder or JSON, then explored with entity enrichment, relationship details, folding, and mapping edits.

8 September 2026
2

Linux Preferences

Doc update

The superscript asterisk was removed from the `nfs4` entry in the Linux preferences documentation.

8 September 2026

Mde Linux Prerequisites

Doc update

The filesystem entries on the Linux prerequisites page were redistributed between the two table columns; the listed entries remain unchanged.

8 September 2026
1

Microsoft Defender for Identity health issues

Doc update

The health alerts article revision date changed, and the Sensor v3.x RPC Audit Misconfigured entry now includes resolution guidance, including verifying the Unified Sensor RPC Audit configuration.

8 September 2026
1

Working With The Regex Engine

Doc update

The article now more clearly explains that it covers supported RegEx syntax, known limitations, and examples for building expressions in content inspection and file policies.

8 September 2026
1

Alerts Azure Storage

Doc update

Seven Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants.

8 September 2026
2

Normalization Develop Parsers

Feature update

The documentation now restricts parsers to the declared source table, one normalized output per source record, and scalar or local static mappings. Cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication are prohibited for parser operations.

8 September 2026

Normalization Create Parsers Ai Agent

Doc update

The documentation now states that parser creation skills normalize each source record independently and preserve record cardinality. Query-local datatable/lookup mappings are allowed when lookup keys are unique, while same-table and cross-table event enrichment are not used.

8 September 2026
1

Data Connector Ui Definitions Reference

Doc update

The data connector UI definitions reference now uses the corrected relative link to the Create a codeless connector documentation.

8 September 2026