Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1187386

Microsoft Defender for Identity alerts transitioning to XDR-based detection platform

Informational

Message ID

MC1187386
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity classic alerts will transition to the XDR detection platform starting mid-December 2025, improving detection accuracy. Admins must update workflows, use new Detector IDs, and reconfigure alert exclusions with XDR Alert Tuning rules. The rollout completes by early January 2026.

Details

Introduction

Microsoft Defender for Identity classic alerts will transition to the XDR detection platform in mid-December 2025. This change improves detection accuracy and performance and aligns with our efforts to enhance security across environments.

When this will happen:

General availability (Production, GCC, and DoD): Rollout will begin in mid-December 2025 and is expected to complete early January.

How this affects your organization:

Who is affected: Admins managing Microsoft Defender for Identity alerts and workflows.

What will happen:

  • Classic MDI alerts will move to the XDR detection platform.
  • Detector IDs will change for specific alerts.
  • Alert exclusions configured in MDI must be reconfigured using XDR Alert Tuning rules.

Affected alerts and new Detector IDs:

Alert TitleDetector ID
Suspected brute-force attack (Kerberos, NTLM)xdr_OnPremBruteforce
Suspected password spray attack (Kerberos, NTLM)xdr_OnPremPasswordSpray
Anomalous SAMR activityxdr_SamrReconnaissanceSecurityAlert

What you can do to prepare:

Action required:

  • Update workflows and automation to use the new XDR Detector IDs.
  • Reconfigure any alert exclusions using XDR Alert Tuning rules.
  • Communicate this change to your security and operations teams.
  • Review Microsoft documentation for XDR Alert Tuning configuration.

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

📅
Published
Nov 17, 2025
Message published to Message Center
✏️
Updated
Nov 17, 2025
Message content updated
🏁
End Date
Feb 10, 2026
Message timeline ends

Tags

#Feature update#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC1192254

Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations

Dec 5, 2025
MC1184997

Microsoft Defender for O365: New email actions available in Advanced Hunting

Nov 12, 2025
MC1194061

IP address changes in Defender for Identity v2.x sensor communication

Dec 10, 2025
MC1193410

Automatic Windows event auditing configuration availability for unified sensors (V3.x)

Dec 9, 2025
MC1181656

Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint

Oct 30, 2025