MC1461704: Microsoft Defender XDR Adds Unified Identity Response Actions Across Linked Accounts

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
52
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Security TeamsCompliance TeamsMicrosoft 365 AdminsTenant AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This introduces a new unified capability for applying identity response actions across linked accounts using Microsoft Defender XDR. Admins need to review RBAC permissions, verify connector setup, validate sensor accounts, and update runbooks, which drives moderate-to-high admin impact and implementation effort. Urgency is moderate because the rollout begins in less than two months and no forced change occurs without admin action. User impact remains low as changes occur in security workflows, not daily user operations.
65
🛡️ Admin Impact
15
👥 User Impact
55
Urgency
60
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Defender XDR adds unified identity response actions so analysts can manage all linked accounts from one place, improving incident handling across multiple identity providers.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review RBAC permissions, verify connectors and configurations, update runbooks, and train analysts on new workflow before rollout.
📅

ROLLOUT TIMELINE

Upcoming:
Mid-October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender XDR: Unified response actions across identity accounts
Message ID: MC1461704

[What and why:]

Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts. Security teams will be able to apply supported response actions to all supported accounts associated with an identity, or to selected accounts, from a single workflow.

Available actions depend on the identity system or connector managing the account and may include:

  • Disable account
  • Enable account
  • Revoke session
  • Mark as compromised
  • Force password change

Supported identity systems and applications include:

  • Active Directory
  • Microsoft Entra ID
  • Okta
  • CyberArk Identity
  • SailPoint Identity Security Cloud
  • Google Workspace
  • Salesforce
  • Box

This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications.

[Rollout schedule:]

  • Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026.

Who is affected

  • Security Operations Center (SOC) analysts
  • Incident responders
  • Identity administrators
  • Administrators managing Microsoft Defender-connected identity systems

Platforms and services

  • Microsoft Defender XDR
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Entra ID
  • Supported third-party identity provider and SaaS application connectors

What will happen

  • Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center.
  • Available response actions vary based on the identity system or connector managing each account.
  • Administrators can review action status in Action center and in audit records generated by the target system.
  • No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action.

[Action required / Recommendations:]

No action is required to enable this capability. However, we recommend that administrators:

  • Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles.
  • Verify Microsoft Defender for Identity action account configuration for Active Directory response actions.
  • If using Microsoft Defender for Identity sensor version 3.x, ensure the sensor is running under the Local System account.
  • Verify that supported identity provider and SaaS application connectors are configured with credentials that allow the intended response actions.
  • Enable Identity Inventory integration in Microsoft Defender for Cloud Apps if SaaS cloud accounts are included in response workflows.
  • Update incident response runbooks and train analysts to verify selected accounts before confirming response actions.

Learn more

Source: Microsoft Message Center • Analysed by MWPro

Share This Update