Reconstruct identity alerts from chronology and entity relationships
Use Investigate alerts in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.
Read the briefingPage 22 of the DSE IT knowledge center, with source-backed guidance and practical next steps.
Production-minded guidance for endpoints, servers, updates, cloud services, administration, and supportable operations.
Use Investigate alerts in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.
Read the briefing
Use Remediation actions in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.
Read the checklist
Use Microsoft Defender for Identity role groups to review this narrow operational decision without extending the source beyond its stated scope.
Read the explainer
Use Manage related identities and accounts in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.
Read the guide
Use Microsoft Defender for Identity health issues to review this narrow operational decision without extending the source beyond its stated scope.
Read the playbook
Use Download and schedule Defender for Identity reports in Microsoft Defender XDR (Preview) to review this narrow operational decision without extending the source beyond its stated scope.
Read the briefing
Use Manage and update Microsoft Defender for Identity sensors to review this narrow operational decision without extending the source beyond its stated scope.
Read the checklist
Use Configure Defender for Identity detection exclusions in Microsoft Defender to review this narrow operational decision without extending the source beyond its stated scope.
Read the explainer
Use View information on the Defender for Identity About page to review this narrow operational decision without extending the source beyond its stated scope.
Read the guide
Use Remove the Microsoft Defender for Identity sensor to review this narrow operational decision without extending the source beyond its stated scope.
Read the playbook