In development
Microsoft Defender for Identity: Unified identity timeline on the Identity page
The updated identity timeline provides security teams with a single chronological view of activity and alerts associated with an identity and its linked accounts. It normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS and cloud activity, and device logons. New fields and filters include Source table, Session ID, and Unique token identifier, with expanded Conditional Access and event context.
Affected: Microsoft 365 Defender, Microsoft Defender
Change history
2026-09-02 · First captured by tracker