MC1187397 High Major change
Microsoft Defender for Endpoint: Threat actor attribution information will be removed from alert page
Summary AI-generated
Threat actor attribution will be removed from Defender for Endpoint alert pages on Jan 12, 2026; details will remain on Incident and Threat Intelligence pages.
Suggested actions AI-generated
- Review incident-based investigation processes
- Update workflows to use Incident or Threat Intelligence pages
- Inform SOC and threat intelligence teams
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1234542 Retirement of “Suspected identity theft (pass-the-ticket)” classic alert
- MC1187386 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
- MC1465771 Microsoft Defender XDR: DLP alerts will be set as behaviors by default
- MC1217649 Endpoint DLP-sensitive data alerting retiring in Defender; use Purview DLP
- MC1411577 Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed
- MC1254554 Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps
Original post from Microsoft
We’d like to inform you that threat actor attribution details will soon be removed from the alert page in Microsoft Defender for Endpoint. This change is designed to improve clarity and focus in alert content. Threat actor attribution is more meaningful and actionable when viewed in the context of the broader incident rather than at the individual alert level.
After this change, attribution details will be available on the Incident page and in the Threat Intelligence section within the Microsoft Defender portal.
When this will happen
January 12, 2026: Threat actor attribution information will be retired from alert pages.
How this affects your organization
Who is affected: Admins and security teams using Microsoft Defender for Endpoint.
What will happen:
- Threat actor attribution will no longer appear on individual alert pages.
- Attribution details will be available on the Incident page and in the Threat Intelligence experience.
- No impact to alert generation, detection logic, or security effectiveness.
What you can do to prepare
- No admin action is required; this change will occur automatically.
- If your workflows currently rely on alert-level actor attribution, review incident-based investigation processes to ensure continuity.
- Update internal workflows, playbooks, or automation rules to retrieve attribution from the Incident page or Threat Intelligence section.
- Inform SOC and threat intelligence teams about this change.
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Threat actor attribution will be removed from Microsoft Defender for Endpoint alert pages on January 12, 2026, and moved to the Incident page and Threat Intelligence section. This change improves alert clarity without affecting detection or security. No admin action is needed, but update workflows accordingly.