Skip to Content

MC1461704 Microsoft Defender XDR Unified response actions across identity accounts

Microsoft Defender XDR is expanding identity response actions into a unified experience across linked accounts. Security teams will be able to apply supported response actions to all supported accounts associated with an identity, or to selected accounts, from a single workflow.

Available actions depend on the identity system or connector managing the account and may include:

  • Disable account
  • Enable account
  • Revoke session
  • Mark as compromised
  • Force password change

Supported identity systems and applications include:

  • Active Directory
  • Microsoft Entra ID
  • Okta
  • CyberArk Identity
  • SailPoint Identity Security Cloud
  • Google Workspace
  • Salesforce
  • Box

This enhancement helps security operations teams respond more quickly and consistently to compromised identities across connected identity providers and SaaS applications.

Microsoft 365 Message Center ID: MC1461704
Last Modified: August 26, 2026
Category: Message Center
Tags: New feature, Admin impact
Status: Launched
Products & Platforms: Microsoft Defender XDR

Rollout schedule

Worldwide, GCC, GCC High, DoD: Rollout begins mid-October 2026 and is expected to complete by mid-October 2026.

Who is affected

  • Security Operations Center (SOC) analysts
  • Incident responders
  • Identity administrators
  • Administrators managing Microsoft Defender-connected identity systems

Platforms and services

  • Microsoft Defender XDR
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Entra ID
  • Supported third-party identity provider and SaaS application connectors

What will happen

  • Authorized analysts can initiate supported response actions from the Identity page, Identity side panel, Advanced Hunting, or Action center.
  • Available response actions vary based on the identity system or connector managing each account.
  • Administrators can review action status in Action center and in audit records generated by the target system.
  • No account changes occur unless an authorized analyst initiates a response action or Microsoft Defender Automatic Attack Disruption applies a supported automated response action.

Action required / Recommendations

No action is required to enable this capability. However, we recommend that administrators:

  • Review and assign the required Microsoft Defender Unified RBAC permissions and Microsoft Entra roles.
  • Verify Microsoft Defender for Identity action account configuration for Active Directory response actions.
  • If using Microsoft Defender for Identity sensor version 3.x, ensure the sensor is running under the Local System account.
  • Verify that supported identity provider and SaaS application connectors are configured with credentials that allow the intended response actions.
  • Enable Identity Inventory integration in Microsoft Defender for Cloud Apps if SaaS cloud accounts are included in response workflows.
  • Update incident response runbooks and train analysts to verify selected accounts before confirming response actions.

Learn more

  • Microsoft Defender for Identity remediation actions
  • Investigate identities and take identity actions in Microsoft Defender XDR
  • Microsoft Defender XDR custom permissions