Microsoft Defender for Identity will update several detections from late September to mid-October 2025 to reduce false positives and improve accuracy, lowering alert noise without requiring configuration changes. Admins should review alert volumes post-rollout and inform their security teams accordingly.
Introduction:
The Microsoft Defender for Identity team is rolling out improvements to several detections based on customer feedback and internal analysis. These updates are designed to reduce alert noise and improve detection accuracy, helping security teams focus on the most actionable threats. An active Microsoft Defender for Identity (MDI) license is required to benefit from these improvements.
When this will happen:
These improvements will begin rolling out gradually starting in late September 2025 and will complete by mid-October 2025.
How this affects your organization:
Who is affected: Admins managing Microsoft Defender for Identity in commercial tenants.
What will happen:
No changes to configuration or policy settings are required.
What you can do to prepare:
Learn more: Security alerts - Microsoft Defender for Identity | Microsoft Learn
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.