Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-11-17 23:46:18
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
—
Action by (AI)
—
Services
Microsoft Defender XDR
Tags
Feature update, Admin impact
Master tags
Security
Roadmap IDs
One-line summary
Defender for Identity classic alerts will shift to the XDR detection platform starting mid-December 2025; update workflows and alert exclusions to use new XDR Detector IDs.
Similar updates
More like thisMC992217 (Updated) Microsoft Defender: Changes to Defender for Cloud Apps alerts
(Updated) Microsoft Defender: Changes to Defender for Cloud Apps alerts Defender for Cloud Apps alerts in Defender XDR will update alert source fields and alert ID prefixes for new alerts, affecting APIs, SIEM, and custom automations; rollout completes by late June 2025. Coming soon for Microsoft Defender for Cloud Apps: A change to alerts.
MC1077861 (Updated) Microsoft Defender for Cloud Apps: SIEM agents will retire
As part of our ongoing convergence process for all Microsoft Defender workloads, we planned to retire SIEM (Security Information and Event Management) agents from Microsoft Defender for Cloud Apps in late December 2025 (previously mid-November) and ending early January 2026 (previously late November 2025). ...t Defender XDR events - Microsoft.
MC1191616 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
Learn more: Microsoft Defender XDR | Microsoft Defender | Microsoft Learn Microsoft Secure Score | Microsoft Defender XDR | Microsoft Defender | Microsoft Learn Compliance considerations No compliance considerations identified, review as appropriate for your organization. Learn more: Microsoft Defender XDR | Microsoft Defender | Microsoft Learn.
MC1179155 (Updated) Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score
(Updated) Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score Microsoft Secure Score adds new improvement actions based on Defender for Identity, recommending password changes for on-prem accounts with leaked credentials; rollout starts early Nov 2025. Introduction To help organizations better assess and improve.
MC1147387 Microsoft Defender for Office 365: Alert experience enhancements for faster triage
Microsoft Defender for Office 365: Alert experience enhancements for faster triage Defender for Office 365 will consolidate related alerts into richer, single alerts starting mid-September 2025, reducing alert fatigue and improving triage without changing detection or workflows. Introduction We’re improving the alert experience in Microsoft.
MC1194061 IP address changes in Defender for Identity v2.x sensor communication
IP address changes in Defender for Identity v2.x sensor communication Defender for Identity v2.x sensors will use new IPs from the AzureAdvancedThreatProtection range starting mid-December 2025; update firewall rules if restricting outbound IPs. [Introduction] As part of ongoing infrastructure and security improvements, Microsoft Defender for.
Details
Summary
Microsoft Defender for Identity classic alerts will transition to the XDR detection platform starting mid-December 2025, improving detection accuracy. Admins must update workflows, use new Detector IDs, and reconfigure alert exclusions with XDR Alert Tuning rules. The rollout completes by early January 2026.
Body (from Message Center)
[Introduction]
Microsoft Defender for Identity classic alerts will transition to the XDR detection platform in mid-December 2025. This change improves detection accuracy and performance and aligns with our efforts to enhance security across environments.
[When this will happen:]
General availability (Production, GCC, and DoD): Rollout will begin in mid-December 2025 and is expected to complete early January.
[How this affects your organization:]
Who is affected: Admins managing Microsoft Defender for Identity alerts and workflows.
What will happen:
- Classic MDI alerts will move to the XDR detection platform.
- Detector IDs will change for specific alerts.
- Alert exclusions configured in MDI must be reconfigured using XDR Alert Tuning rules.
Affected alerts and new Detector IDs:
| Alert Title | Detector ID |
|---|---|
| Suspected brute-force attack (Kerberos, NTLM) | xdr_OnPremBruteforce |
| Suspected password spray attack (Kerberos, NTLM) | xdr_OnPremPasswordSpray |
| Anomalous SAMR activity | xdr_SamrReconnaissanceSecurityAlert |
[What you can do to prepare:]
Action required:
- Update workflows and automation to use the new XDR Detector IDs.
- Reconfigure any alert exclusions using XDR Alert Tuning rules.
- Communicate this change to your security and operations teams.
- Review Microsoft documentation for XDR Alert Tuning configuration.
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Raw JSON (for debugging)
Expand/collapse the full payload below.
Show/hide raw
{
"snapshot_item": {
"action_required_by": null,
"ai_action_required_by": null,
"ai_actions": [
"Update workflows for new XDR Detector IDs",
"Reconfigure alert exclusions using XDR Alert Tuning",
"Inform security and operations teams",
"Review XDR Alert Tuning documentation"
],
"ai_master_tags": [
"Security"
],
"ai_model": "gpt-4.1",
"ai_summary": "Defender for Identity classic alerts will shift to the XDR detection platform starting mid-December 2025; update workflows and alert exclusions to use new XDR Detector IDs.",
"ai_topics": [
"Defender"
],
"category": "stayInformed",
"details_map": {
"Summary": "Microsoft Defender for Identity classic alerts will transition to the XDR detection platform starting mid-December 2025, improving detection accuracy. Admins must update workflows, use new Detector IDs, and reconfigure alert exclusions with XDR Alert Tuning rules. The rollout completes by early January 2026."
},
"id": "MC1187386",
"importance": 0,
"is_major_change": false,
"last_modified": "2025-11-17T23:46:18Z",
"ms_products": [
"Defender"
],
"platforms": null,
"roadmap_ids": [],
"services": [
"Microsoft Defender XDR"
],
"severity": "normal",
"tags": [
"Feature update",
"Admin impact"
],
"title": "Microsoft Defender for Identity alerts transitioning to XDR-based detection platform"
}
}