Microsoft Defender for Identity
Incidents and response

Adjust alert thresholds | Microsoft Defender for Identity

In brief

The page’s publication date and custom metadata were updated. It also includes a warning that reverting to default is irreversible and discards threshold-level changes.

What Defender admins need to know

Administrators reviewing threshold settings should be aware that reverting to defaults permanently loses their changes.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Adjust alert thresholds

For example, if you have NAT or VPN, we recommend that you consider any changes to relevant detections carefully, including Suspected DCSync attack (replication of directory services) and Suspected identity theft detections.

To define your alert thresholds:

  1. In Microsoft Defender XDR

    To define your alert thresholds:

    1. In Microsoft Defender XDR, go to Settings > Identities > Adjust alert thresholds.

    2. Select Apply changes to save changes.

    3. To reset all alerts to the default threshold (High), select Revert to default and then Apply changes.

    1. To reset all alerts to the default threshold (High), select Revert to default and then Apply changes.

    Switch to Recommended test mode

    Switch to Recommended test mode