Skip to Content

MC1461705 Microsoft Defender XDR Unified identity timeline on the Identity page

We are enhancing the Timeline tab on the Identity page in Microsoft Defender to provide security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. This enhancement helps security operations center (SOC) analysts, incident responders, and security administrators investigate identities more efficiently by consolidating relevant events from multiple Microsoft security data sources into one investigation experience.

The updated timeline normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering capabilities, and event details will help analysts more quickly understand identity-related activity and security risks.

Microsoft 365 Message Center ID: MC1461705
Last Modified: August 26, 2026
Category: Message Center
Tags: New feature, Admin impact
Status: Launched
Products & Platforms: Microsoft Defender XDR

Rollout schedule

Worldwide, GCC, GCC High, DoD: Rollout begins mid-September 2026 and is expected to complete by mid-October 2026.

Impact on your organization

This update affects SOC analysts, incident responders, and security administrators who investigate identities in the Microsoft Defender portal.

After rollout:

The Timeline tab on the Identity page will display a consolidated sequence of activity and alerts for an identity and its linked accounts.

Microsoft Entra sign-ins and Microsoft Graph audit events will include relevant risk and Conditional Access information when available.

New filtering and investigation fields will be available, including:

  • Source table
  • Session ID
  • Unique token identifier
  • Conditional Access
  • Target
  • Additional information

Expanded event context will help analysts investigate identity-related activity without pivoting across multiple data sources.

The timeline will automatically refresh when linked accounts change.

This update does not modify existing security policies, user accounts, permissions, or configurations.

Action required / Recommendations

No action is required to enable the core timeline experience.

To help your organization take advantage of this enhancement, we recommend that you:

  • Inform SOC and incident response teams about the updated Timeline experience.
  • Review investigation runbooks that require analysts to pivot between multiple Advanced Hunting tables.
  • If you use supported SaaS cloud accounts, enable Identity inventory integration in Microsoft Defender for Cloud Apps by navigating to Settings > Cloud Apps.
  • Confirm that analysts have the appropriate permissions to access identity investigation data in the Microsoft Defender portal.

Learn more

  • Investigate an identity
  • Enable Identity inventory integration