M365 Change Tracker

← Home

Advanced Hunting — changes & security (22)

Roadmap, security and documentation changes captured for Advanced Hunting.

PreviewMicrosoft Defender XDRAdvanced Hunting

Local AI agent discovery on Windows endpoints

Local AI agent discovery on Windows endpoints: as part of the Defender AI agents experience, Microsoft Defender now automatically discovers supported local AI agents running on onboarded Windows devices - including coding agents and IDE extensions, desktop AI assistants, local AI runtimes, and agent platforms. Discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting, giving security teams visibility into local AI agent usage across the organization. For more information, see Discover local AI agents.

GA×2 recordsMicrosoft Defender XDRDefender for CloudAdvanced Hunting

The following advanced hunting schema tables are now generally available

The following advanced hunting schema tables are now generally available: The DisruptionAndResponseEvents table contains information about automatic attack disruption events in Microsoft Defender XDR. The `CloudAuditEvents` table contains information about cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud. The `CloudDnsEvents` table contains information about DNS activity events from cloud infrastructure environments. The `CloudProcessEvents` table contains information about process events in multicloud hosted environments.

PreviewMicrosoft Defender XDRAdvanced Hunting

The `AgentsInfo` table in advanced hunting is now available in preview.

The `AgentsInfo` table in advanced hunting is now available in preview. The `AIAgentsInfo` table is transitioning to this new table, which provides a unified schema that supports agent inventory and governance for all agent types, including Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. Microsoft Agent 365 customers should use the `AgentsInfo` table today. The `AIAgentsInfo` table remains accessible until July 1, 2026. Update your queries to use `AgentsInfo` before this date. For more information, see Advanced hunting schema - Naming changes.

defenderMicrosoft Defender XDRAdvanced Hunting

The hunting graph in advanced hunting now includes new identity-focused…

The hunting graph in advanced hunting now includes new identity-focused predefined scenarios. These scenarios help you discover attack paths, privilege escalation routes, and credential access risks across on-premises and cloud environments, including Kerberoast and AS-REP roast paths, domain compromise routes, OAuth application risks, and guest user access to cloud resources.

PreviewMicrosoft Defender XDRAdvanced Hunting

The `AIAgentsInfo` table in advanced hunting now includes additional columns

The `AIAgentsInfo` table in advanced hunting now includes additional columns that provide deeper visibility into AI agents operating in your Microsoft 365 environment. These fields expand coverage beyond Copilot Studio to all agent types, including Microsoft Foundry, third-party marketplace, and custom line-of-business agents.

Preview×3 recordsMicrosoft Defender XDRDefender for CloudAdvanced Hunting

The following advanced hunting schema tables are now available for preview

The following advanced hunting schema tables are now available for preview: The `CloudDnsEvents` table contains information about DNS activity events from cloud infrastructure environments. The `CloudPolicyEnforcementEvents` table contains policy enforcement evaluation decisions and metadata of security gating events for various cloud platforms protected by the organization's Microsoft Defender for Cloud.

PreviewMicrosoft Defender XDRAdvanced Hunting

The `BehaviorInfo` and `BehaviorEntities` tables in advanced hunting now…

The `BehaviorInfo` and `BehaviorEntities` tables in advanced hunting now include additional columns and information about behavior data types and alerts from User and Entity Behavior Analytics (UEBA), providing more insights on the relationships between identified behaviors and entities. Learn more about UEBA behaviors

PreviewMicrosoft Defender XDRAdvanced Hunting

You can now enrich your custom detection rules by creating dynamic alert…

In advanced hunting, you can now enrich your custom detection rules by creating dynamic alert titles and descriptions, select more impacted entities, and add custom details to display in the alert side panel. Microsoft Sentinel customers that are onboarded to Microsoft Defender also now have the option to customize the alert frequency when the rule is based only on data that is ingested to Sentinel.

GA×2 recordsMicrosoft Defender XDRAdvanced Hunting

You can now view all your user-defined rules—both custom detection rules and…

In advanced hunting, you can now view all your user-defined rules—both custom detection rules and analytics rules—in the Detection rules page. This feature also brings the following improvements: You can now filter for *every* column (in addition to Frequency and Organizational scope). For multiworkspace organizations that onboard multiple workspaces to Microsoft Defender, you can now view the Workspace ID column and filter by workspace. You can now view the details pane even for analytics rules. You can now perform the following actions on analytics rules: Turn on/off, Delete, Edit. (GA) The Sensitivity label filter is now available in the Incidents and Alerts queues in the Microsoft Defender portal. This filter lets you filter incidents and alerts based on the sensitivity label assigned to the affected resources. For more information, see Filters in the incident queue and Investigate alerts.

PreviewMicrosoft Defender XDRAdvanced Hunting

The `DisruptionAndResponseEvents` table, now available in advanced hunting,…

The `DisruptionAndResponseEvents` table, now available in advanced hunting, contains information about automatic attack disruption events in Microsoft Defender XDR. These events include both block and policy application events related to triggered attack disruption policies, and automatic actions that were taken across related workloads. Increase your visibility and awareness of active, complex attacks disrupted by attack disruption to understand the attacks' scope, context, impact, and actions taken.

defenderMicrosoft Defender XDRAdvanced Hunting

Defender portal users who onboard Microsoft Sentinel and enable the User and…

Defender portal users who onboard Microsoft Sentinel and enable the User and Entity Behavior Analytics (UEBA) can now take advantage of the new unified `IdentityInfo` table in advanced hunting. This latest version now includes the largest possible set of fields common to both Defender and Azure portals.

PreviewMicrosoft Defender XDRAdvanced Hunting

The following advanced hunting schema tables are now available for preview to…

The following advanced hunting schema tables are now available for preview to help you look through Microsoft Teams events and related information: The MessageEvents table contains details about messages sent and received within your organization at the time of delivery The MessagePostDeliveryEvents table contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization The MessageUrlInfo table contains information about URLs sent through Microsoft Teams messages in your organization