Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1137610

Microsoft Defender for Identity alerts transitioning to XDR-based detection platform

Plan for Change

Message ID

MC1137610
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity classic alerts will transition to the XDR detection platform on September 18, 2025, improving detection accuracy and performance. Users must update workflows with new Detector IDs and reconfigure alert exclusions using XDR Alert Tuning rules.

Details

On September 18, 2025, the following Microsoft Defender for Identity classic alerts will be moved to the MDI XDR detection platform. This transition is part of our ongoing effort to enhance detection capabilities across the environment. The move to XDR enables:

  • Improved detection logic helping to reduce false positives.
  • Enhanced performance 

MDI Classic Alerts moving to MDI XDR alerts

Alert titleExternal ID
Active Directory attributes Reconnaissance using LDAP2210
User and IP address reconnaissance2012
Account enumeration reconnaissance2003
Suspected brute-force attack (LDAP)2004
Suspicious network connection over Encrypting File System Remote Protocol2416

New MDI XDR Alerts

Alert TitleDetector ID
Active Directory attributes Reconnaissance using LDAPxdr_LdapSensitiveAttributeReconnaissanceSecurityAlert
User and IP address reconnaissance (SMB)xdr_SmbSessionEnumeration
Account enumeration reconnaissance in AD FSxdr_AccountEnumerationHintSecurityAlertAdfs
Account enumeration in reconnaissance in Kerberos xdr_AccountEnumerationHintSecurityAlertKerberos
Account enumeration reconnaissance in NTLMxdr_AccountEnumerationHintSecurityAlertNtlm
Suspected brute-force attack (LDAP)xdr_LdapBindBruteforce
Suspicious network connection over Encrypting File System Remote Protocolxdr_SuspiciousConnectionOverEFSRPC

Action Required

  • If you are using any of the MDI classic Alert IDs in your workflows or automation, please update them to use the corresponding Detector IDs listed above.
  • If you have defined alert exclusions in the MDI settings, you will need to reconfigure those exclusions using XDR Alert Tuning rules.

Timeline

📅
Published
Aug 18, 2025
Message published to Message Center
✏️
Updated
Aug 18, 2025
Message content updated
⚠️
Action Required By
Sep 17, 2025
Action deadline
🏁
End Date
Oct 30, 2025
Message timeline ends

Tags

#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1154297

Microsoft Defender for Identity: New recommendations for Microsoft Secure Score

Sep 16, 2025
MC1150118

Microsoft Defender for Office 365: New records in Streaming API and Sentinel EmailEvents table

Sep 8, 2025
MC1169078

Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities

Oct 9, 2025
MC1147387

Microsoft Defender for Office 365: Alert experience enhancements for faster triage

Sep 3, 2025
MC1155429

Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score

Sep 18, 2025