A new page explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.
Sentinel normalization guidance now prohibits cross-table enrichment and preserves record cardinality
The period’s most consequential update was revised Sentinel parser guidance: parsers are limited to their declared source table, one normalized output per source record, and scalar or local static mappings. Cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication are explicitly excluded. Companion AI-agent guidance permits query-local lookup mappings only when keys are unique. Defender XDR also added detailed advanced-hunting graph guidance, while seven Azure Storage alert entries now use Informational severity. Other changes were mainly editorial, with added troubleshooting steps for the Sensor v3.x RPC Audit Misconfigured alert.
- Sentinel parser guidance draws strict normalization boundaries
Sentinel · Cloud and workloads
The revised guidance limits parsers to the declared source table and one normalized output per source record, using scalar or local static mappings. It explicitly excludes cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication; source filtering must use fields from the current event.
- AI-agent parser guidance preserves record-by-record output
Sentinel · Cloud and workloads
Parser-creation skills are described as normalizing each source record independently while preserving record cardinality. Query-local datatable or lookup mappings are allowed only when lookup keys are unique; same-table and cross-table event enrichment are not used.
- Advanced hunting receives dedicated graph-mapping guidance
Defender XDR · Hunting and detection
A new page explains how to prepare query results, configure graph nodes and edges, apply relationship conditions, and use recognized entity types and identifiers for Defender enrichment.
- Advanced hunting results guidance expands visual relationship workflows
Defender XDR · Hunting and detection
The updated article documents mapping results to nodes and edges through Builder or JSON, then exploring entity enrichment, relationship details, folding, and mapping edits without writing a graph-specific query.
- Seven Azure Storage alert entries now show Informational severity
Defender for Cloud · Cloud and workloads
The documented severity for seven Azure Storage alerts changed from High, Medium, or Low variants to Informational. Administrators should use the revised labels when reviewing and prioritizing these documented alerts.
Review custom Sentinel parsers and connectors against the documented source-table, record-cardinality, and enrichment limits. For AI-agent parser creation, use unique lookup keys and plan for record-by-record normalization; no required configuration change is stated. Use the revised Informational labels when reviewing documented Azure Storage alerts. Administrators troubleshooting the Identity health alert should follow the added resolution guidance, including verification of Unified Sensor RPC Audit configuration. The Linux formatting, Regex scope, filesystem-layout, and connector-link edits require no action.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Defender XDR
2 updatesAdvanced Hunting Query Results
New featureAdvanced hunting results can be mapped to nodes and edges using a Builder or JSON, then explored with entity enrichment, relationship details, folding, and mapping edits.
Microsoft Defender for Endpoint
2 updatesLinux Preferences
Doc updateThe superscript asterisk was removed from the `nfs4` entry in the Linux preferences documentation.
Mde Linux Prerequisites
Doc updateThe filesystem entries on the Linux prerequisites page were redistributed between the two table columns; the listed entries remain unchanged.
Microsoft Defender for Identity
1 updateThe health alerts article revision date changed, and the Sensor v3.x RPC Audit Misconfigured entry now includes resolution guidance, including verifying the Unified Sensor RPC Audit configuration.
Working With The Regex Engine
Doc updateThe article now more clearly explains that it covers supported RegEx syntax, known limitations, and examples for building expressions in content inspection and file policies.
Microsoft Defender for Cloud
1 updateAlerts Azure Storage
Doc updateSeven Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants.
Microsoft Sentinel
3 updatesNormalization Develop Parsers
Feature updateThe documentation now restricts parsers to the declared source table, one normalized output per source record, and scalar or local static mappings. Cross-table enrichment, watchlists, multi-value expansion, joins, aggregation, and deduplication are prohibited for parser operations.
Normalization Create Parsers Ai Agent
Doc updateThe documentation now states that parser creation skills normalize each source record independently and preserve record cardinality. Query-local datatable/lookup mappings are allowed when lookup keys are unique, while same-table and cross-table event enrichment are not used.
Data Connector Ui Definitions Reference
Doc updateThe data connector UI definitions reference now uses the corrected relative link to the Create a codeless connector documentation.
