SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Defender for Identity sensor (all editions) - Microsoft primary source

Microsoft Defender for Identity Sensor v3.x GA and Key Security Updates

Microsoft Defender for Identity sensor version 3.x is now generally available, offering enhanced coverage, performance, and easier management. Several security posture assessments and alert improvements have been introduced, including vulnerability detection for CVE-2020-1472, risk level integrations, and new Graph-based API support for sensor management and response actions.

What changed

- GA release of Defender for Identity sensor v3.x with improved coverage and performance. - Transition of several alerts to unified Microsoft Defender alerting format. - Introduced identity-related security posture assessments like inactive service accounts and discoverable passwords. - Added near real-time Microsoft Entra ID risk level to Defender for Identity. - New Graph API preview for sensor actions and remediation. - Bug fixes and improved detection accuracy, including noise reduction. - Deprecation warning for sensor support on Windows Server 2008 R2 starting August 15, 2022.

Why it matters operationally

Operators should plan to upgrade to sensor v3.x to benefit from better performance and coverage. Monitor newly unified alerts and incorporate new security posture assessments for enhanced threat detection. Review deprecated platform usage and migrate off Windows Server 2008 R2. Utilize new Graph APIs for automation and response. Expect reduced alert noise and improved accuracy in detections.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Upgrade Defender for Identity sensors to version 3.x where supported.
  • Review transitioned alerts in the unified alerting system and update monitoring rules accordingly.
  • Leverage new security posture assessments to identify inactive service accounts and discoverable passwords.
  • Incorporate Microsoft Entra ID risk level data in investigations and custom detections.
  • Begin planning migration off Windows Server 2008 R2 for sensor compatibility.
  • Explore and implement new Graph API features for sensor management and incident response.
  • Review and adjust alert handling in response to updated detection behaviors reducing noise.

Related vulnerabilities

CVE-2020-1472

KQL hunting context

With the new alerts transitioning to the unified format and enhanced detection logic, updating hunting queries using KQL to leverage updated alert names and enriched data is recommended.

Source links

https://learn.microsoft.com/en-us/defender-for-identity/whats-new-archive