Summary
Details
Updated May 19, 2025: We have updated the content. Thank you for your patience.
Coming soon: We will unify the Microsoft Defender for Identity (MDI) and Microsoft Sentinel IdentityInfo tables in Advanced Hunting into a single table.
With this unification, we are adding new identity attributes from the Sentinel UEBA service while also adjusting to support third-party Identity Providers (IDPs). Some of these updates include breaking changes, which may require you to update your existing queries.
[When this will happen:]
General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out early May 2025 and expect to complete by late May 2025.
[How this will affect your organization:]
After this rollout, identity-related insights will be enriched with these new columns:
| Column name | Type | Description | Comment |
|---|---|---|---|
|
String | Active Directory object ID of the user | New column |
|
String | User type in Microsoft Entra ID. Possible values: |
New column |
|
String | Status of the user's risk. Possible values: |
New column |
|
Dynamic | Security attributes of the user account in Active Directory | New column |
To help you adjust existing queries, this table shows how Sentinel UEBA fields map to the new unified IdentityInfo table’s schema:
| Sentinel UEBA Column | Unified IdentityInfo Column |
Comments |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Values might be different |
|
|
Values might be different |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Breaking Changes
Changes to support third-party identity providers (IDPs):
- To accommodate third-party IDPs, we are modifying these existing columns:
| Column Name | Type | Change |
|---|---|---|
|
String | Replaces the |
|
Dynamic | New column listing identity sources. Possible values: |
[What you need to do to prepare:]
To ensure a smooth transition, we recommend you:
- Review the new columns and their impact on your security workflows.
- Prepare to update and adjust any queries, custom alert rules, playbooks, workbooks, watchlists or automations that reference the
IdentityInfotable and would be impacted by the changes. - You may also want to update any relevant internal documentation you might have.
This rollout will happen automatically by the specified dates with no admin action required before the rollout.
Learn more:
- IdentityInfo table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn
- The Power of a Unified SIEM+XDR IdentityInfo Schema | Microsoft Community Hub
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.