Skip to main content
๐Ÿฆ‰
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
๐Ÿฆ‰
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

ยฉ 2026 M365 Message Center. Created with โค by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center โ€ข Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1183015

Fix/Update Microsoft Sentinel Account Entity Naming to avoid inconsistent account identification in incidents and alerts

Message ID

MC1183015
View in Admin Center

Services

Microsoft Defender XDR

Summary

By July 1, 2026, update Microsoft Sentinel analytic rules, automations, workbooks, and queries to use the new account entity naming precedence: UPN prefix โ†’ name โ†’ display name. Failure to update may cause issues in incidents, alerts, dashboards, and playbooks referencing account names.

Details

Updated November 19, 2025: We have updated the timing of this change below. Thank you for your patience.

On July 1, 2026, you may encounter issues if you haven't updated your analytic rules, automation rules/playbooks, workbooks, hunting queries, or custom integrations to be precedence-aware for account entity naming. We've standardized the account entity naming logic in Microsoft Sentinel incidents and alerts, where the account entity naming priority is: UPN prefix โ†’ name โ†’ display name. Please update your queries and automations to use the new precedence pattern.

You are receiving this message because our reporting indicates your organization may be using Microsoft Sentinel incidents, alerts (AlertV3), or related automation.

When this will happen:

July 1, 2026 (previously February 13, 2026)

How this will affect your organization:

If you don't fix this problem, these queries, automations, dashboards, and reports that reference account names may be affected:

  • Analytics (KQL) that filter by, join on, or normalize account names
  • Automation rules & playbooks (e.g., Logic Apps) that map Account.Name or compare it to other identity fields
  • Workbooks & dashboards that show account name or aggregate by that value
  • Hunting queries that coalesce or parse account identity fields
  • Any users or systems relying on display name as the account identifier

What you need to do to prepare:

To fix this problem you need to update your KQL queries and automation logic to use the new precedence-aware pattern for account entity naming. Specifically, use a coalesce pattern (e.g., coalesce(Name, DisplayName)) wherever you reference the account name, and validate your workbooks, dashboards, and playbooks against the new logic. Test changes in a nonproduction workspace before rollout.

Timeline

Published
Nov 5, 2025
Message published to Message Center
Updated
Nov 19, 2025
Message content updated
Action Required By
Jul 1, 2026
Action deadline
End Date
Aug 10, 2026
Message timeline ends

Tags

#Updated message#Admin impact

Category

Plan for Change

Related Messages

Similar updates

MC1187403

Automatic Windows event auditing configuration now available for unified sensors (V3.x)

Nov 17, 2025
MC1187390

Unified sensor (v3.x) รขโ‚ฌโ€œ new Remote Procedure Call (RPC) configuration health alert for Microsoft Defender for Identity

Nov 17, 2025
MC1179155

Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score

Oct 24, 2025
MC1166867

Microsoft Defender for Office 365: Enhancing the quarantine email preview experience

Oct 6, 2025
MC1171845

Microsoft Defender for Office 365: Enhancing the quarantine experience for administrators

Oct 13, 2025