Microsoft Defender XDR
Incidents and response

Configure email alert notifications in Microsoft Defender XDR

In brief

The page title and description now refer to Microsoft Defender XDR, setup step numbering was corrected, and a warning explains that deleting a notification rule permanently stops its future email notifications.

What Defender admins need to know

Administrators should note that deleted notification rules must be recreated if removed accidentally.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure alert notifications in Microsoft Defender XDR

[!INCLUDE Microsoft Defender XDR rebranding]

  1. In the navigation pane, select Settings > Endpoints > General > Email notifications.

  2. Click Add item.

  3. Specify the General information:

    • Rule name - Specify a name for the notification rule.
    • Include organization name - Specify the customer name that appears on the email notification.
    • Include tenant-specific portal link - Adds a link with the tenant ID to allow access to a specific tenant.
  4. Click Save notification rule.

Delete a notification rule

To delete a notification rule, follow these steps:

  1. Select the notification rule you'd like to delete.

  2. Click Delete.

  1. Select the notification rule you'd like to delete.

  2. Click Delete.