Additional Microsoft Defender tools and services that provide security across various platforms and environments
Hi Jeet Patel,
In the unified Microsoft Defender portal, incident modifications (status changes, assignments, comments, etc.) are no longer written to AzureActivity or SentinelAudit as they were in the standalone Sentinel (Azure portal) experience.
Instead, Defender incident and portal actions are audited via Microsoft 365 Unified Audit Log (UAL) and surfaced through Advanced Hunting primarily in the following table:
- CloudAppEvents: - This is the primary table to track who did what, when, and how for Defender portal actions. Microsoft documentation confirms that:
- Defender XDR activities flow into the Unified Audit Log
- These activities are then exposed in CloudAppEvents when the Microsoft 365 connector is enabled.
- Enable Microsoft 365 connector
- Enable Microsoft 365 connector
- Insufficient permissions
- For programmatic approach I recommend Microsoft Purview Unified Audit Log for Audit Trail (who/what/when/how)
Reference:
https://learn.microsoft.com/en-us/defender-office-365/audit-log-search-defender-portal
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.