Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1234542

Retirement of “Suspected identity theft (pass-the-ticket)” classic alert

Plan for Change
Major Change

Message ID

MC1234542
View in Admin Center

Services

Microsoft Defender XDR

Summary

The “Suspected identity theft (pass-the-ticket)” classic alert will retire between March 18-22, 2026, replaced by the “Pass-the-Ticket (PtT) attack” XDR alert. Existing alerts remain accessible. No admin action is required, but update workflows, alert tuning, and documentation accordingly. No compliance issues noted.

Details

Introduction

To streamline our alert catalog and focus investment on our unified Microsoft Defender XDR detection capabilities, we’re retiring the “Suspected identity theft (pass‑the‑ticket)” classic alert (External ID: 2018). This retirement aligns with our move toward consolidated XDR alerting and improved detection fidelity.

We recommend using the “Pass‑the‑Ticket (PtT) attack” alert (Detector ID: xdr_PassTheTicketAttack), where ongoing development and enhancements will continue.

When this will happen

We’ll retire the classic alert between March 18, 2026 and March 22, 2026.

How this affects your organization

Who is affected:

  • Organizations using Microsoft Defender for Identity within Microsoft Defender XDR services.
  • Security operations teams and administrators who rely on classic alerting.

What will happen:

  • The “Suspected identity theft (pass‑the‑ticket)” classic alert (External ID: 2018) will stop generating new alerts after retirement.
  • Existing historical alerts will remain accessible in your environment.
  • The “Pass‑the‑Ticket (PtT) attack” XDR detector (ID: xdr_PassTheTicketAttack) will continue to operate and should be used going forward.
  • No changes will be made to user experiences outside security operations.

What you can do to prepare

No admin action is required for this change, but we recommend the following to ensure continuity in your security workflows:

  • Update alert triage processes, workflows, and automation to reference the XDR detector IDs.
  • Reconfigure alert exclusions or tuning rules using XDR Alert Tuning.
  • Notify security and operations teams of the upcoming retirement.
  • Update internal documentation to reference the new alert name and detector ID.
  • Review Microsoft documentation for configuring XDR Alert Tuning.

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.

Timeline

Published
Feb 18, 2026
Message published to Message Center
Updated
Feb 18, 2026
Message content updated
Action Required By
Mar 16, 2026
Action deadline
End Date
Apr 22, 2026
Message timeline ends

Tags

#User impact#Admin impact#Retirement

Category

Plan for Change

Related Messages

Similar updates

MC1245219●

Microsoft Defender for iOS: End of support for iOS 16 devices

Mar 5, 2026
MC1220762●

Retirement notice: MDE and XDR Advanced Hunting APIs retiring; migrate to Microsoft Graph Security API

Jan 22, 2026
MC1222977●

Microsoft Defender for Android: End of support for Android 10 devices

Jan 28, 2026
MC1221927●

Microsoft Defender for Android ending support for enrolled personal profiles

Jan 23, 2026
MC1217649●

Endpoint DLP-sensitive data alerting retiring in Defender; use Purview DLP

Jan 14, 2026