capability

Identity Alerts and Incidents

Defender for Identity contributes identity-based alerts and incident context to Microsoft Defender XDR for attacks such as credential theft, lateral movement, and privilege escalation.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellGapNo product-specific PowerShell automation surface is recorded for this capability yet.
REST APIGapNo supported REST configuration surface is recorded for this capability yet.
GraphSupported Reference
ARMGapNo ARM resource is recorded for this capability.
BicepGapNo Bicep resource is recorded for this capability.
TerraformGapAlerts and incidents are operational records exposed through Graph/Defender XDR, not Terraform-managed resources.
GitHub ActionsSupported Reference
Azure DevOpsSupported Reference