Microsoft Defender XDR
General

Investigate Alerts

In brief

The page updates headings, anchors, wording, and tag-color descriptions. It also notes that alert suppression is incompatible with custom detections and recommends fine-tuning them to avoid false positives.

What Defender admins need to know

Administrators using custom detections should account for this suppression limitation when reviewing alert volume and tuning detections.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • admindeeplinkDEFENDER
  • sfi-ga-nochange ms.topic: how-to ms.date: 06/15/07/02/2026 appliesto:
  • Microsoft Defender XDR
  • Microsoft Sentinel in the Microsoft Defender portal

:::image type="content" source="media/investigate-alerts/alerts-page-defender-small.png" alt-text="The Alerts section in the Microsoft Defender portal" lightbox="media/investigate-alerts/alerts-page-defender.png":::

Alerts from different Microsoft security solutions like Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, Defender for Cloud, Defender for Identity, Defender for Cloud Apps, Defender XDR, App Governance, Microsoft Entra ID Protection, and Microsoft Data Loss Prevention appear here.in the Alerts queue.

By default, the alerts queue in the Microsoft Defender portal displays the new and in progress alerts from the last seven days. The most recent alert is at the top of the list so you can see it first. You can also find the total number of alerts in the queue indicated beside the Search bar. The total number of alerts varies depending on the filters used in the queue.

An alert can have system tags and/or custom tags with certain colorwhite, red, or black backgrounds. Custom tags use the white background while system tags typically use red or black background colors. System tags identify the following in an incident:

  • A type of attack, like ransomware or credential phishing
  • Automatic actions, like automatic investigation and response and automatic attack disruption

:::image type="content" source="media/investigate-alerts/alerts-search-bar-small.png" alt-text="Highlighting the search bar in the Alerts queue" lightbox="media/investigate-alerts/alerts-search-bar.png":::

PermissionsRequired permissions to investigate alerts

Access to alerts in the Microsoft Defender portal is controlled by Microsoft Defender permissions and role assignments.

RoleRequired role assignments

You can receive the permissions required to view alerts through these role assignments:

  • Alert story, which is the chain of events and alerts related to this alert in chronological order
  • Summary details

Throughout an alert page, you can select the ellipses (...) beside any entity to see available actions, such as linking the alert to another incident. The list of available actions depends on the type of alert.selected alert's type.

Alert sources

Microsoft Defender XDR alerts come from solutions like Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, the app governance add-on for Microsoft Defender for Cloud Apps, Microsoft Entra ID Protection, and Microsoft Data Loss Prevention. You might notice alerts with prepended characters in the alert.alert ID. The following table provides guidance to help you understand the mapping of alert sources based on the prepended character on the alert.

:::image type="content" source="media/investigate-alerts/alert-service-settings-entra.png" alt-text="Screenshot of Microsoft Entra ID Protection alerts setting in the Microsoft Defender portal." lightbox="media/investigate-alerts/alert-service-settings-entra.png":::

You can access Alert service settings from the Incidents page in the Microsoft Defender portal.

Once you've selected an entity of interest, the details page changes to display information about the selected entity type, historic information when it's available, and options to take action on this entity directly from the alert page.

Manage alert status and classification

To manage an alert, select Manage alert in the summary details section of the alert page. For a single alert, here's an example of the Manage alert pane.

  • In August 2022, previously supported alert determination values (Apt and SecurityPersonnel) were deprecated and are no longer available via the API.

  • One way of managing alerts is through the use of tags. The tagging capability for Microsoft Defender for Office 365 is currently in preview, rolling out incrementally.

Currently, modified tag names are only applied to alerts created after the update. Alerts that were generated before the modification will not reflect the updated tag name.

:::image type="content" source="media/investigate-alerts/alerts-ss-alerts-select-related.png" lightbox="media/investigate-alerts/alerts-ss-alerts-select-related.png" alt-text="Screenshot of managing related alerts in the Microsoft Defender portal":::

If similar alerts were already classified in the past, you can save time by using Microsoft Defender XDR recommendations to learn how previously classified similar alerts were resolved. From the summary details section, select Recommendations.

:::image type="content" source="media/investigate-alerts/alerts-ss-alerts-recommendations.png" lightbox="media/investigate-alerts/alerts-ss-alerts-recommendations.png" alt-text="Screenshot of an example of selecting recommendations for an alert":::

You can also create your own custom alert tuning rules to perform one of the following actions when specific conditions are met:

  • Hide alert: Suppresses the alert and prevents incident creation. Hidden alerts remain in AlertInfo and AlertEvidence tables. The Hide alert action is only applicable for Defender for Endpoint alerts.
  • Resolve alert: Automatically resolves the alert and related incidents. Matching alerts and their associated incidents are triggered with resolved status.
  • Set as behavior: Converts matching signals into behaviors. They won’t appear in the alert queue or trigger incidents. Data remains in BehaviorInfo and BehaviorEntities tables for hunting. This action isn't supported for Defender for Cloud or Microsoft Defender for Office 365 alerts.

After creating your alert tuning rule from an alert details page, in the Successful rule creation page that appears, add any of the alert-related IOCs as indicators to an allow list to prevent them from being blocked in the future. IOCs that are configured as part of the alert tuning rule are selected by default. For example:

  1. Add a file to the Select evidence (IOC) to allow list. By default, the file that triggered the alert is already selected.

Next steps

For incidents that remain active, continue investigating by following Investigate incidents.

Related content