Identity Security in the Defender Portal: What’s New

Summer vacation has a way of creating space for the things that get pushed aside during busy, stressful months. This year, I used that time to dive into something I’d wanted to explore for a while: the new identity security features in the Microsoft Defender portal — and actually get them configured. Here’s an overview of the new additions and how to use them:

Correlate / link accounts (using rules or manually)

A single person often has multiple accounts spread across different systems. Let’s take “Eddard Stark” (a demo user) as an example. He could have any combination of the following:

  • A default Active Directory account
  • An Entra ID account synced from AD
  • A dedicated cloud admin account in Entra ID
  • A Salesforce admin account

You can now link these accounts directly in the Defender portal. Navigate to Assets → click on the main user account, and open the “Observed in organization” tab. Here you can see which accounts Defender has already discovered and linked automatically. If something doesn’t look right, you can unlink an account or manually add one that was missed.

Linked accounts in the Observed in organization tab of the Defender portal

Additionally, if you want to link accounts at scale, there is an option under Settings → Identities → Account Correlation Rules. Here you can create custom correlation rules for accounts that don’t share strong common identifiers. For example, you can define a rule to match accounts based on the portion before or after the @ in the UPN. This means that accounts like martin@test.ch and martin@sistercompanyoftest.ch can be automatically linked together, even if they sit in different domains.

Account correlation rules under Settings, Identities in the Defender portal

Thanks to connectors for Okta, SailPoint, and other third-party platforms, you can even pull in external accounts and include them in the linked-accounts picture. The following screenshot is taken from the Microsoft video, as 3rd party apps were not available in my tenant:

Third-party accounts from Okta and SailPoint in the linked-accounts view (Microsoft demo screenshot)

This is a powerful feature that gives Defender significantly more context about a user’s footprint across your environment. With that context, it can predict the blast radius if one of the linked accounts is compromised — and will trigger an alert displaying that blast radius so you can act quickly.


Sensitive tags on identities and groups

Defender now automatically tags identities and groups based on a classification mechanism running in the background. Tags are applied automatically — for example, “Sensitive” or “Privileged Entra PIM Roles” — but there are several other tags available depending on the classification result.

Automatically applied sensitivity tags on an identity in the Defender portal

In addition, identities can be tagged manually as Sensitive if needed. To do this, navigate to Settings → Identities → Sensitive, where you can apply the Sensitive tag to any account directly. The screenshots show that the “Administrator” account was tagged as Sensitive manually and received the “Domain Admin” tag automatically. Although this account is not synced to Entra ID, it can still be discovered by Defender for Identity and will appear in your identity assets.

Administrator account manually tagged as Sensitive Administrator account showing the automatic Domain Admin tag

Both automatic and manual tags serve as an immediate visual indicator of which identities and groups deserve closer attention, and are also used to trigger alerts within Defender.


Risk score

Note: A higher score indicates greater risk! Navigating to Assets → Identities in the Defender portal and clicking a user now reveals a dedicated Risk Score tab. This provides a comprehensive overview including:

  • Risk summary and score
  • All systems where that user has accounts (sourced from linked accounts, referred to as “account sets”)
  • The likelihood of compromise with additional details
  • Current alerts

Another sample screenshot from the video, as this wasn’t available in my tenant yet:

Risk Score tab for an identity in the Defender portal (Microsoft demo screenshot)


Summary by Security Copilot

On the right side of the Risk Score page, you’ll find a summary generated by Security Copilot. I’ll admit — I used to think I could piece this together myself just as quickly. But as these summaries have become richer and more detailed, I’ve come to appreciate them as a starting point for deeper investigation. They save time and often surface context you might otherwise overlook.

Security Copilot summary on the identity Risk Score page




Link to the Microsoft video:

Redefining identity security for the modern enterprise – YouTube

Share this:

Leave a Reply

Your email address will not be published. Required fields are marked *