Review the update and plan any required actions before rollout.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
Mid-October 2026
📢 Official Microsoft Message Center Announcement
Microsoft Defender XDR: Unified response actions across identity accounts
Message ID: MC1461704
[What and why:]
Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts. Security teams will be able to apply supported response actions to all supported accounts associated with an identity, or to selected accounts, from a single workflow.
Available actions depend on the identity system or connector managing the account and may include:
- Disable account
- Enable account
- Revoke session
- Mark as compromised
- Force password change
Supported identity systems and applications include:
- Active Directory
- Microsoft Entra ID
- Okta
- CyberArk Identity
- SailPoint Identity Security Cloud
- Google Workspace
- Salesforce
- Box
This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications.
[Rollout schedule:]
- Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026.
Who is affected
- Security Operations Center (SOC) analysts
- Incident responders
- Identity administrators
- Administrators managing Microsoft Defender-connected identity systems
Platforms and services
- Microsoft Defender XDR
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Entra ID
- Supported third-party identity provider and SaaS application connectors
What will happen
- Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center.
- Available response actions vary based on the identity system or connector managing each account.
- Administrators can review action status in Action center and in audit records generated by the target system.
- No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action.
[Action required / Recommendations:]
No action is required to enable this capability. However, we recommend that administrators:
- Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles.
- Verify Microsoft Defender for Identity action account configuration for Active Directory response actions.
- If using Microsoft Defender for Identity sensor version 3.x, ensure the sensor is running under the Local System account.
- Verify that supported identity provider and SaaS application connectors are configured with credentials that allow the intended response actions.
- Enable Identity Inventory integration in Microsoft Defender for Cloud Apps if SaaS cloud accounts are included in response workflows.
- Update incident response runbooks and train analysts to verify selected accounts before confirming response actions.
Learn more
- Microsoft Defender for Identity remediation actions
- Investigate identities and take identity actions in Microsoft Defender XDR
- Microsoft Defender XDR custom permissions
Source: Microsoft Message Center • Analysed by MWPro


