Microsoft Defender XDR
Incidents and response

Alert policies in the Microsoft Defender portal

In brief

The article now notes that some default alert policies contain filters not shown in the Microsoft Defender portal. These filters can affect whether activities match conditions and trigger alerts, and the article provides a PowerShell command to view them.

What Defender admins need to know

Administrators may need to inspect default policy properties with Get-ProtectionAlert when portal settings do not explain alert behavior.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Alert policies in the Microsoft Defender portal

Information governance alert policies