Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Defender XDR: Unified identity timeline on the Identity page

Message ID
MC1461705
View in Message Center
Service
Microsoft Defender XDR
Category
Plan for Change
Tags
New featureAdmin impact
Rollout
September 2026October 2026

Summary

Microsoft Defender XDR is enhancing the Identity page's Timeline tab to provide a unified, chronological view of identity-related activities and alerts from multiple Microsoft security sources. Rolling out mid-September to mid-October 2026, it offers improved context, filtering, and automatic updates without changing existing policies. No action is required to enable it.

Details

[What and Why:]

We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience.

The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks.

[Rollout schedule:]

  • Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026.

[Impact on your organization:]

This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal.

After rollout:

  • The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts.
  • Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available.
  • New filtering and investigation fields will be available, including:
    • Source table
    • Session ID
    • Unique token identifier
    • Conditional Access
    • Target
    • Additional information
  • Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources.
  • The timeline will automatically refresh when linked accounts change.

This update does not modify existing security policies, user accounts, permissions, or configurations.

[Action required / Recommendations:]

No action is required to enable the core timeline experience.

To help your organization take advantage of this enhancement, we recommend that you:

  • Inform SOC and incident response teams about the updated Timeline experience.
  • Review investigation runbooks that require analysts to pivot between multiple Advanced Hunting tables.
  • If you use supported SaaS cloud accounts, enable Identity inventory integration in Microsoft Defender for Cloud Apps by navigating to Settings > Cloud Apps.
  • Confirm that analysts have the appropriate permissions to access identity investigation data in the Microsoft Defender portal.

Learn more

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.