{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/record-defender-identity-workspace-id-name-support-proxy-changes/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
        "slug": "record-defender-identity-workspace-id-name-support-proxy-changes",
        "url": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/record-defender-identity-workspace-id-name-support-proxy-changes/"
        },
        "title": "Record the Defender for Identity workspace ID and name for support and proxy changes",
        "summary": "Use View information on the Defender for Identity About page to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:12:47+00:00",
        "modified_at": "2026-08-27T13:04:09+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 610,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of View information on the Defender for Identity About page",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "View information on the Defender for Identity About page",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/settings-about",
            "published_on": "2026-07-02",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to connect an official requirement or behavior to observable evidence: Record the Defender for Identity workspace ID and name for support and proxy changes. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/settings-about\" target=\"_blank\" rel=\"noopener noreferrer\">View information on the Defender for Identity About page</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>The Defender for Identity About page reports the workspace ID and name, latest available sensor version, assigned license count, and identities active during the preceding 28 days. The research record locates this support at <strong>Information shown on the Defender for Identity About page &gt; details list</strong>.</li>\n<li>Microsoft directs administrators to use the About-page identifiers for troubleshooting or support and to supply the workspace name when setting proxy or firewall connectivity. The research record locates this support at <strong>Information shown on the Defender for Identity About page &gt; paragraph following the details list</strong>.</li>\n</ul>\n<p>The source support ends with the statements listed above. Use them to examine Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health in the applicable environment, not to imply a wider guarantee.</p>\n<h2>What the source does not establish</h2>\n<p>Workspace identifiers support inventory and escalation; they do not prove sensor connectivity, health, license entitlement, data ingestion, or support-case resolution. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations before translating the source into an operational decision.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Information shown on the Defender for Identity About page &gt; details list</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Information shown on the Defender for Identity About page &gt; paragraph following the details list</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>Which deployed instance of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health will be compared with the source, and why that instance?</li>\n<li>How will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations?</li>\n<li>Who approves the conclusion, exception, test window, and rollback threshold?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health, observed and expected states, owner, and reason for deviation.</p>\n<p>For an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.</p>\n<h2>Verification and evidence</h2>\n<p>Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations <strong>Information shown on the Defender for Identity About page &gt; details list</strong>; <strong>Information shown on the Defender for Identity About page &gt; paragraph following the details list</strong>. Favor sensor inventory, service and action-account permissions, health alerts, connectivity tests, portal state, and controlled detection tests, linked to stable identifiers, time, and operator.</p>\n<p>Keep before-state evidence, approval, test or change result, exceptions, and after-state evidence together. Use an approved lab, window, or nonproduction path for risky tests. Set a recheck trigger for version, architecture, dependency, vendor, incident, or ownership change. A check proves only what was observed.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/settings-about\" target=\"_blank\" rel=\"noopener noreferrer\">View information on the Defender for Identity About page</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to connect an official requirement or behavior to observable evidence: Record the Defender for Identity workspace ID and name for support and proxy changes. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official View information on the Defender for Identity About page from Microsoft supports the following bounded statements:\n\nThe Defender for Identity About page reports the workspace ID and name, latest available sensor version, assigned license count, and identities active during the preceding 28 days. The research record locates this support at Information shown on the Defender for Identity About page > details list.\nMicrosoft directs administrators to use the About-page identifiers for troubleshooting or support and to supply the workspace name when setting proxy or firewall connectivity. The research record locates this support at Information shown on the Defender for Identity About page > paragraph following the details list.\n\nThe source support ends with the statements listed above. Use them to examine Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health in the applicable environment, not to imply a wider guarantee.\nWhat the source does not establish\nWorkspace identifiers support inventory and escalation; they do not prove sensor connectivity, health, license entitlement, data ingestion, or support-case resolution. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Information shown on the Defender for Identity About page > details list, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Information shown on the Defender for Identity About page > paragraph following the details list, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health, observed and expected states, owner, and reason for deviation.\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Information shown on the Defender for Identity About page > details list; Information shown on the Defender for Identity About page > paragraph following the details list. Favor sensor inventory, service and action-account permissions, health alerts, connectivity tests, portal state, and controlled detection tests, linked to stable identifiers, time, and operator.\nKeep before-state evidence, approval, test or change result, exceptions, and after-state evidence together. Use an approved lab, window, or nonproduction path for risky tests. Set a recheck trigger for version, architecture, dependency, vendor, incident, or ownership change. A check proves only what was observed.\nOfficial references\n\nView information on the Defender for Identity About page — Microsoft",
        "content_markdown": "Use this document to connect an official requirement or behavior to observable evidence: Record the Defender for Identity workspace ID and name for support and proxy changes. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [View information on the Defender for Identity About page](https://learn.microsoft.com/en-us/defender-for-identity/settings-about) from Microsoft supports the following bounded statements:\n\n- The Defender for Identity About page reports the workspace ID and name, latest available sensor version, assigned license count, and identities active during the preceding 28 days. The research record locates this support at Information shown on the Defender for Identity About page > details list.\n\n- Microsoft directs administrators to use the About-page identifiers for troubleshooting or support and to supply the workspace name when setting proxy or firewall connectivity. The research record locates this support at Information shown on the Defender for Identity About page > paragraph following the details list.\n\nThe source support ends with the statements listed above. Use them to examine Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health in the applicable environment, not to imply a wider guarantee.\n\n## What the source does not establish\n\nWorkspace identifiers support inventory and escalation; they do not prove sensor connectivity, health, license entitlement, data ingestion, or support-case resolution. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations before translating the source into an operational decision.\n\n## Applicability questions\n\n- For source statement 1 at Information shown on the Defender for Identity About page > details list, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Information shown on the Defender for Identity About page > paragraph following the details list, which observable configuration, record, or test can confirm applicability here?\n\n- Which deployed instance of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health will be compared with the source, and why that instance?\n\n- How will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations?\n\n- Who approves the conclusion, exception, test window, and rollback threshold?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health, observed and expected states, owner, and reason for deviation.\n\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\n\n## Verification and evidence\n\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Information shown on the Defender for Identity About page > details list; Information shown on the Defender for Identity About page > paragraph following the details list. Favor sensor inventory, service and action-account permissions, health alerts, connectivity tests, portal state, and controlled detection tests, linked to stable identifiers, time, and operator.\n\nKeep before-state evidence, approval, test or change result, exceptions, and after-state evidence together. Use an approved lab, window, or nonproduction path for risky tests. Set a recheck trigger for version, architecture, dependency, vendor, incident, or ownership change. A check proves only what was observed.\n\n## Official references\n\n- [View information on the Defender for Identity About page](https://learn.microsoft.com/en-us/defender-for-identity/settings-about) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
                "url": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Record the Defender for Identity workspace ID and name for support and proxy changes",
                        "item": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/#article",
                "identifier": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
                "url": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/",
                "headline": "Record the Defender for Identity workspace ID and name for support and proxy changes",
                "description": "Use View information on the Defender for Identity About page to review this narrow operational decision without extending the source beyond its stated…",
                "abstract": "Use View information on the Defender for Identity About page to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to connect an official requirement or behavior to observable evidence: Record the Defender for Identity workspace ID and name for support and proxy changes. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official View information on the Defender for Identity About page from Microsoft supports the following bounded statements:\n\nThe Defender for Identity About page reports the workspace ID and name, latest available sensor version, assigned license count, and identities active during the preceding 28 days. The research record locates this support at Information shown on the Defender for Identity About page > details list.\nMicrosoft directs administrators to use the About-page identifiers for troubleshooting or support and to supply the workspace name when setting proxy or firewall connectivity. The research record locates this support at Information shown on the Defender for Identity About page > paragraph following the details list.\n\nThe source support ends with the statements listed above. Use them to examine Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health in the applicable environment, not to imply a wider guarantee.\nWhat the source does not establish\nWorkspace identifiers support inventory and escalation; they do not prove sensor connectivity, health, license entitlement, data ingestion, or support-case resolution. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Information shown on the Defender for Identity About page > details list, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Information shown on the Defender for Identity About page > paragraph following the details list, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of Defender for Identity workspaces, sensors, directory-service accounts, action accounts, network paths, roles, and deployment health, observed and expected states, owner, and reason for deviation.\nFor an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, certificates, domain-controller resources, network capture, cloud connectivity, and security operations in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Information shown on the Defender for Identity About page > details list; Information shown on the Defender for Identity About page > paragraph following the details list. Favor sensor inventory, service and action-account permissions, health alerts, connectivity tests, portal state, and controlled detection tests, linked to stable identifiers, time, and operator.\nKeep before-state evidence, approval, test or change result, exceptions, and after-state evidence together. Use an approved lab, window, or nonproduction path for risky tests. Set a recheck trigger for version, architecture, dependency, vendor, incident, or ownership change. A check proves only what was observed.\nOfficial references\n\nView information on the Defender for Identity About page — Microsoft",
                "datePublished": "2026-08-27T12:12:47+00:00",
                "dateModified": "2026-08-27T13:04:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/record-defender-identity-workspace-id-name-support-proxy-changes/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Record the Defender for Identity workspace ID and name for support and proxy changes"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 610,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "View information on the Defender for Identity About page",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/settings-about",
                    "datePublished": "2026-07-02"
                }
            }
        ]
    }
}