Microsoft Defender for Identity
Identity protection

Detection exclusions in Microsoft Defender XDR

In brief

The documentation now states that existing exclusions do not automatically carry over when detections move to the Microsoft Defender XDR detection engine. Once moved, those exclusions stop applying and previously suppressed alerts can reappear.

What Defender admins need to know

Review affected exclusions and migrate them to matching alert tuning rules to preserve detection tuning and avoid unexpected alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Defender for Identity detection exclusions in Microsoft Defender XDR

This article explains how to configure Microsoft Defender for Identity detection exclusions in Microsoft Defender.

Microsoft Defender for Identity enables the exclusion of specific IP addresses, computers, domains, or users from a number of detections.

  • Among the most common domains with Suspicious communication over DNS alerts, we observed the domains that were most frequently excluded from the alert. These domains are added to the exclusions list by default, but you have the option to remove them.

How to add detection exclusions

To add detection exclusions, complete the following steps.

  1. Sign in to the Microsoft Defender portal :::image type="content" source="media/detect-exclusions/detection-rule-details.png" alt-text="Screenshot of the detection rule details.":::
    1. To add an exclusion, select the Excluded entities button.

    2. Choose the exclusion type. Different excluded entities are available for each rule. They includetype, such as users, devices, domains, andor IP addresses. Each rule supports different entity types. In this example, the choices are Exclude devices and Exclude IP addresses.

      :::image type="content" source="media//detect-exclusions/exclude-devices-or-ip-addresses.png" alt-text="Screenshot showing the options to exclude devices or IP addresses.":::

      :::image type="content" source="media//detect-exclusions/exclude-ip-addresses.png" alt-text="Screenshot showing the exclusion of IP addresses.":::

    3. OnceAfter you've added add exclusions, you can export the list or remove the exclusions by returningthem. Return to the Excluded entities button. In this example, we've returned toselect Exclude devices. To export the list, select the down arrow button.

      :::image type="content" source="media//detect-exclusions/return-to-exclude-devices.png" alt-text="Screenshot showing how to return to exclude devices.":::

    4. To delete an exclusion, select the exclusion and select the trash icon. Deleting an exclusion removes it immediately and may cause related alerts to resume.

      :::image type="content" source="media//detect-exclusions/delete-exclusion.png" alt-text="Screenshot showing how to delete an exclusion.":::

Global excluded entities

You can now also configure exclusions by using Global excluded entities. Global exclusions allowlet you to defineexclude certain entities (IP addresses, subnets, devices, or domains) to be excluded acrossfrom all of the detections Microsoft Defender for Identity has. So fordetections. For example, if you exclude a device, the exclusion willapplies only apply to those detections that haveuse device identification as part of the detection.identification.

  1. Select Global excluded entities to see the categories of entities that you can exclude.