Identity Alerts and Incidents
Defender for Identity contributes identity-based alerts and incident context to Microsoft Defender XDR for attacks such as credential theft, lateral movement, and privilege escalation.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Gap | No supported REST configuration surface is recorded for this capability yet. |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Alerts and incidents are operational records exposed through Graph/Defender XDR, not Terraform-managed resources. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |