# Plan Defender for Identity around fixed workspace geolocation and 180-day retention

> Use Privacy with Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.

- Canonical URL: https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-27T12:15:07+00:00
- Modified: 2026-08-27T12:56:25+00:00
- Last reviewed by DSE: 2026-08-26
- Resource type: Guide
- DSE priority: Advisory
- Topics: Cybersecurity, IT, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

Use Privacy with Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.

## Potentially affected

Teams, systems, services, or facilities within the stated scope of Privacy with Microsoft Defender for Identity

## DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

## Article

Use this document to connect an official requirement or behavior to observable evidence: Plan Defender for Identity around fixed workspace geolocation and 180-day retention. Only the official source and traced locations below supply facts. Confirm applicability before acting.

## Source fact:

The official [Privacy with Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance) from Microsoft supports the following bounded statements:

- A Defender for Identity workspace is automatically created in the data center geographically closest to the Microsoft Entra ID tenant and cannot later be moved; its geolocation appears under Settings > Identity > About. The research record locates this support at Data location > customer data storage bullets.

- Defender for Identity retains data visible across the portal for 180 days. The research record locates this support at Data retention.

- After the license grace or suspended period ends, Microsoft says the data is erased and made unrecoverable no later than 180 days after contract termination or expiration. The research record locates this support at Data retention.

These statements are the factual basis for this document. Do not extend them into a broader assurance. Review identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows only where the source and recorded environment align.

## What the source does not establish

The service’s location and retention statements do not establish an organization’s legal retention duty, independent backup, export completeness, or recovery capability. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing before translating the source into an operational decision.

## Applicability questions

- For source statement 1 at Data location > customer data storage bullets, which observable configuration, record, or test can confirm applicability here?

- For source statement 2 at Data retention, which observable configuration, record, or test can confirm applicability here?

- For source statement 3 at Data retention, which observable configuration, record, or test can confirm applicability here?

- What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?

- Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?

- What result would disprove the working assumption and return the issue to the owner?

## DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.

For an approved change, define prerequisites, a limited test path, success and stop conditions, monitoring, and rollback. Check Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing in design order. Protect credentials, keys, recovery material, personal data, and sensitive topology in evidence.

## Verification and evidence

Build a reproducible chain from Data location > customer data storage bullets; Data retention; Data retention to the observed environment. Useful domain evidence includes alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure; label every item with scope, timestamp, collector, and stable identifier.

Retain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.

## Official references

- [Privacy with Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance) — Microsoft

## Primary reference

- Name: Privacy with Microsoft Defender for Identity
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-for-identity/privacy-compliance
- Source publication date: 2025-09-28

## Citation and use

Preferred citation: “Plan Defender for Identity around fixed workspace geolocation and 180-day retention,” DSE Security, https://update.dsesecurity.com/updates/plan-defender-identity-fixed-geolocation-180-day-retention/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
