{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/plan-defender-identity-fixed-geolocation-180-day-retention/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
        "slug": "plan-defender-identity-fixed-geolocation-180-day-retention",
        "url": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/plan-defender-identity-fixed-geolocation-180-day-retention/"
        },
        "title": "Plan Defender for Identity around fixed workspace geolocation and 180-day retention",
        "summary": "Use Privacy with Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:15:07+00:00",
        "modified_at": "2026-08-27T12:56:25+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 583,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Privacy with Microsoft Defender for Identity",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Privacy with Microsoft Defender for Identity",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance",
            "published_on": "2025-09-28",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to connect an official requirement or behavior to observable evidence: Plan Defender for Identity around fixed workspace geolocation and 180-day retention. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy with Microsoft Defender for Identity</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>A Defender for Identity workspace is automatically created in the data center geographically closest to the Microsoft Entra ID tenant and cannot later be moved; its geolocation appears under Settings &gt; Identity &gt; About. The research record locates this support at <strong>Data location &gt; customer data storage bullets</strong>.</li>\n<li>Defender for Identity retains data visible across the portal for 180 days. The research record locates this support at <strong>Data retention</strong>.</li>\n<li>After the license grace or suspended period ends, Microsoft says the data is erased and made unrecoverable no later than 180 days after contract termination or expiration. The research record locates this support at <strong>Data retention</strong>.</li>\n</ul>\n<p>These statements are the factual basis for this document. Do not extend them into a broader assurance. Review identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows only where the source and recorded environment align.</p>\n<h2>What the source does not establish</h2>\n<p>The service&#8217;s location and retention statements do not establish an organization&#8217;s legal retention duty, independent backup, export completeness, or recovery capability. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing before translating the source into an operational decision.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Data location &gt; customer data storage bullets</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Data retention</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 3 at <strong>Data retention</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?</li>\n<li>Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?</li>\n<li>What result would disprove the working assumption and return the issue to the owner?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.</p>\n<p>For an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.</p>\n<h2>Verification and evidence</h2>\n<p>Build a reproducible chain from <strong>Data location &gt; customer data storage bullets</strong>; <strong>Data retention</strong>; <strong>Data retention</strong> to the observed environment. Useful domain evidence includes alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure; label every item with scope, timestamp, collector, and stable identifier.</p>\n<p>Retain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy with Microsoft Defender for Identity</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to connect an official requirement or behavior to observable evidence: Plan Defender for Identity around fixed workspace geolocation and 180-day retention. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Privacy with Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nA Defender for Identity workspace is automatically created in the data center geographically closest to the Microsoft Entra ID tenant and cannot later be moved; its geolocation appears under Settings > Identity > About. The research record locates this support at Data location > customer data storage bullets.\nDefender for Identity retains data visible across the portal for 180 days. The research record locates this support at Data retention.\nAfter the license grace or suspended period ends, Microsoft says the data is erased and made unrecoverable no later than 180 days after contract termination or expiration. The research record locates this support at Data retention.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows only where the source and recorded environment align.\nWhat the source does not establish\nThe service’s location and retention statements do not establish an organization’s legal retention duty, independent backup, export completeness, or recovery capability. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Data location > customer data storage bullets, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Data retention, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Data retention, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\nWhich condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\nVerification and evidence\nBuild a reproducible chain from Data location > customer data storage bullets; Data retention; Data retention to the observed environment. Useful domain evidence includes alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure; label every item with scope, timestamp, collector, and stable identifier.\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\nOfficial references\n\nPrivacy with Microsoft Defender for Identity — Microsoft",
        "content_markdown": "Use this document to connect an official requirement or behavior to observable evidence: Plan Defender for Identity around fixed workspace geolocation and 180-day retention. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Privacy with Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance) from Microsoft supports the following bounded statements:\n\n- A Defender for Identity workspace is automatically created in the data center geographically closest to the Microsoft Entra ID tenant and cannot later be moved; its geolocation appears under Settings > Identity > About. The research record locates this support at Data location > customer data storage bullets.\n\n- Defender for Identity retains data visible across the portal for 180 days. The research record locates this support at Data retention.\n\n- After the license grace or suspended period ends, Microsoft says the data is erased and made unrecoverable no later than 180 days after contract termination or expiration. The research record locates this support at Data retention.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows only where the source and recorded environment align.\n\n## What the source does not establish\n\nThe service’s location and retention statements do not establish an organization’s legal retention duty, independent backup, export completeness, or recovery capability. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing before translating the source into an operational decision.\n\n## Applicability questions\n\n- For source statement 1 at Data location > customer data storage bullets, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Data retention, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 3 at Data retention, which observable configuration, record, or test can confirm applicability here?\n\n- What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\n\n- Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\n\n- What result would disprove the working assumption and return the issue to the owner?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\n\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\n\n## Verification and evidence\n\nBuild a reproducible chain from Data location > customer data storage bullets; Data retention; Data retention to the observed environment. Useful domain evidence includes alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure; label every item with scope, timestamp, collector, and stable identifier.\n\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\n\n## Official references\n\n- [Privacy with Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
                "url": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan Defender for Identity around fixed workspace geolocation and 180-day retention",
                        "item": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/#article",
                "identifier": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
                "url": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/",
                "headline": "Plan Defender for Identity around fixed workspace geolocation and 180-day retention",
                "description": "Use Privacy with Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
                "abstract": "Use Privacy with Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to connect an official requirement or behavior to observable evidence: Plan Defender for Identity around fixed workspace geolocation and 180-day retention. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Privacy with Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nA Defender for Identity workspace is automatically created in the data center geographically closest to the Microsoft Entra ID tenant and cannot later be moved; its geolocation appears under Settings > Identity > About. The research record locates this support at Data location > customer data storage bullets.\nDefender for Identity retains data visible across the portal for 180 days. The research record locates this support at Data retention.\nAfter the license grace or suspended period ends, Microsoft says the data is erased and made unrecoverable no later than 180 days after contract termination or expiration. The research record locates this support at Data retention.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows only where the source and recorded environment align.\nWhat the source does not establish\nThe service’s location and retention statements do not establish an organization’s legal retention duty, independent backup, export completeness, or recovery capability. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Data location > customer data storage bullets, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Data retention, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Data retention, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\nWhich condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\nVerification and evidence\nBuild a reproducible chain from Data location > customer data storage bullets; Data retention; Data retention to the observed environment. Useful domain evidence includes alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure; label every item with scope, timestamp, collector, and stable identifier.\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\nOfficial references\n\nPrivacy with Microsoft Defender for Identity — Microsoft",
                "datePublished": "2026-08-27T12:15:07+00:00",
                "dateModified": "2026-08-27T12:56:25+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan Defender for Identity around fixed workspace geolocation and 180-day retention"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 583,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Privacy with Microsoft Defender for Identity",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance",
                    "datePublished": "2025-09-28"
                }
            }
        ]
    }
}