M365 Change Tracker

← All changes · defender

Update

Microsoft Sentinel customers using the Defender portal, or the Azure portal with the Microsoft Sentinel Defender XDR data connector, now also benefit from Microsoft Threat Intelligence alerts that highlight activity from nation-state actors, major ransomware campaigns, and fraudulent operations.

Why it matters: Upcoming change

What to do: To view these alert types, you must have the Security Administrator or higher role.

Microsoft Sentinel customers using the Defender portal, or the Azure portal with the Microsoft Sentinel Defender XDR data connector, now also benefit from Microsoft Threat Intelligence alerts that highlight activity from nation-state actors, major ransomware campaigns, and fraudulent operations. To view these alert types, you must have the Security Administrator or higher role. The Service Source, Detection Source, and Product Name values for these alerts are listed as *Microsoft Threat Intelligence*. For more information, see Incidents and alerts in the Microsoft Defender portal.

Source updated 2025-11-01

Affected: Microsoft Defender XDR

View at Microsoft →