Coming soon: We will unify the Microsoft Defender for Identity (MDI) and Microsoft Sentinel IdentityInfo
tables in Advanced Hunting into a single table.
With this unification, we are adding new identity attributes from the Sentinel UEBA service while also adjusting to support third-party Identity Providers (IDPs). Some of these updates include breaking changes, which may require you to update your existing queries.
When this will happen:
General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out early May 2025 and expect to complete by late May 2025.
How this will affect your organization:
After this rollout, identity-related insights will be enriched with these new columns:
Column name | Type | Description | Comment |
---|---|---|---|
|
String | Active Directory object ID of the user | New column |
|
String | User type in Microsoft Entra ID. Possible values: |
New column |
|
String | Status of the user's risk. Possible values: |
New column |
|
Dynamic | Security attributes of the user account in Active Directory | New column |
To help you adjust existing queries, this table shows how Sentinel UEBA fields map to the new unified IdentityInfo
table’s schema:
Sentinel UEBA Column | Unified IdentityInfo Column |
Comments |
---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Values might be different |
|
|
Values might be different |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Breaking Changes
Changes to support third-party identity providers (IDPs):
Column Name | Type | Change |
---|---|---|
|
String | Replaces the |
|
Dynamic | New column listing identity sources. Possible values: |
What you need to do to prepare:
To ensure a smooth transition, we recommend you:
IdentityInfo
table and would be impacted by the changes.
This rollout will happen automatically by the specified dates with no admin action required before the rollout.
Learn more: IdentityInfo table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn (will be updated before rollout)
Before rollout, we will update this post with new documentation.