Microsoft Defender for Identity alerts transitioning to XDR-based detection platform

Message Center ID: MC1137610
Microsoft Defender XDR
Plan for Change
Feature update Admin impact
September 17, 2025
September 2025

Summary

Microsoft Defender for Identity classic alerts will transition to the XDR detection platform on September 18, 2025, improving detection accuracy and performance. Users must update workflows with new Detector IDs and reconfigure alert exclusions using XDR Alert Tuning rules.

Details

On September 18, 2025, the following Microsoft Defender for Identity classic alerts will be moved to the MDI XDR detection platform. This transition is part of our ongoing effort to enhance detection capabilities across the environment. The move to XDR enables:

  • Improved detection logic helping to reduce false positives.
  • Enhanced performance 

MDI Classic Alerts moving to MDI XDR alerts

Alert titleExternal ID
Active Directory attributes Reconnaissance using LDAP2210
User and IP address reconnaissance2012
Account enumeration reconnaissance2003
Suspected brute-force attack (LDAP)2004
Suspicious network connection over Encrypting File System Remote Protocol2416

New MDI XDR Alerts

Alert TitleDetector ID
Active Directory attributes Reconnaissance using LDAPxdr_LdapSensitiveAttributeReconnaissanceSecurityAlert
User and IP address reconnaissance (SMB)xdr_SmbSessionEnumeration
Account enumeration reconnaissance in AD FSxdr_AccountEnumerationHintSecurityAlertAdfs
Account enumeration in reconnaissance in Kerberos xdr_AccountEnumerationHintSecurityAlertKerberos
Account enumeration reconnaissance in NTLMxdr_AccountEnumerationHintSecurityAlertNtlm
Suspected brute-force attack (LDAP)xdr_LdapBindBruteforce
Suspicious network connection over Encrypting File System Remote Protocolxdr_SuspiciousConnectionOverEFSRPC

Action Required

  • If you are using any of the MDI classic Alert IDs in your workflows or automation, please update them to use the corresponding Detector IDs listed above.
  • If you have defined alert exclusions in the MDI settings, you will need to reconfigure those exclusions using XDR Alert Tuning rules.

Change History

No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.