ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · checked 01:09 UTC Customize Public modeDiscuss ChangeIntel on Discord

Microsoft's edit ·

Stub Docs for Complex type changes and new AuditRRecordType adddition (#29059)

Microsoft's commit message in microsoftgraph/microsoft-graph-docs-contrib · commit 83ae8c9 · +4 −0 lines · also on GitHub

⋯ 278 unchanged lines
279279 - Use the [Create manualAlert](/graph/api/security-alert-post-manualalert?view=graph-rest-beta&preserve-view=true) method to create a manual security alert with specified entities and metadata. The new [manualAlert](/graph/api/resources/security-manualalert?view=graph-rest-beta&preserve-view=true) resource type derives from [alert](/graph/api/resources/security-alert?view=graph-rest-beta&preserve-view=true) and uses the [entityDefinitionInput](/graph/api/resources/security-entitydefinitioninput?view=graph-rest-beta&preserve-view=true) complex type to specify associated entities.
280280 - Added the **tenantId** property to the [userAccount](/graph/api/resources/security-useraccount?view=graph-rest-beta&preserve-view=true) resource to provide the Entra home tenant ID for the compromised user account indicated in a [security alert](/graph/api/resources/security-alert?view=graph-rest-beta&preserve-view=true) where the alert evidence is related to a [processEvidence](/graph/api/resources/security-processevidence?view=graph-rest-beta&preserve-view=true), [userEvidence](/graph/api/resources/security-userevidence?view=graph-rest-beta&preserve-view=true), or [mailboxEvidence](/graph/api/resources/security-mailboxevidence?view=graph-rest-beta&preserve-view=true).
281281
282 +### Security | Audit log query
283 +
284 +Expanded audit log coverage with 28 new [auditData](/graph/api/resources/security-auditdata?view=graph-rest-beta&preserve-view=true) derived types and corresponding [auditLogRecordType](/graph/api/resources/security-auditlogrecordtype?view=graph-rest-beta&preserve-view=true) enumeration members. Query audit events for AI and Copilot services (Dragon Copilot, Security Copilot, Copilot session sharing), security and compliance workloads (Defender for AI, threat submission entities, compliance policy grading), and productivity services (Fabric policy, Viva Glint campaigns, Azure AI Search, Teams user concerns, Spark Core). Added the **dynamicProperties** property of type [auditRecordTypeDictionary](/graph/api/resources/security-auditrecordtypedictionary?view=graph-rest-beta&preserve-view=true) to enable access to workload-specific audit event properties.
285 +
282286 ### Security | Custom detection rules
283287
284288 - Updated the [custom detection rules API](/graph/api/resources/security-detectionrule?view=graph-rest-beta&preserve-view=true) in Microsoft 365 Defender with new capabilities, including: Infrastructure-as-code (IaC) support through user-defined IDs, custom run frequency, flexible entity mapping, custom alert details, and configurable response actions.
⋯ 64 unchanged lines

Microsoft's Markdown source from microsoftgraph/microsoft-graph-docs-contrib, © Microsoft Corporation, under CC BY 4.0. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:19 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 11 Oct 01:09 UTC · 252 of 253 readable · 252 fully read · documentation 391/391 current