Microsoft Defender for Identity
Identity protection

Investigate alerts in Microsoft Defender for Identity

In brief

The article now refers to the alert details side pane, identifies Defender for Identity as the capability tuned by alert classification, and clarifies the tabs and Related Entities data in exported Excel alert reports. The metadata and date were also updated.

What Defender admins need to know

No action is required. Administrators can use the clarified guidance when investigating alerts and reviewing exported reports.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For more information about differences in how alerts are presented in the Defender portal, see View and manage alerts.

Take action from the details pane

Once you've selected an alert of interest, the details side pane changes to display information about the selected alert, historic information when it's available, and offer recommended actions to take action on this alert.

After completing your investigation, return to the selected alert, mark its status as Resolved, and classify it as either False alert or True alert. Classifying alerts helps tune this capabilityDefender for Identity to provide more true alerts and lessfewer false alerts.

Advanced security alert investigation

All involved entities, including accounts, computers, and resources are listed, separated by their role. Details are provided for the source, destination, or attacked entity, depending on the alert.

Most oftabs in the tabsexported Excel alert report include the following data per entity:

  • Name
  • Details
    • Network Activities
    • Event Activities

Some alerts haveexported Excel alert reports include extra tabs, such as details about:

  • Attacked accounts when the suspected attack used Brute Force.
  • Domain Name System (DNS) servers when the suspected attacked involved network mapping reconnaissance (DNS).

Related entities

In each alert, the last tab provides theEach alert includes a Related Entities. Related entities are tab that lists all entities involved in a suspicious activity, without separating them by the separation of the "role" they played in the alert. Each entity has two Json files, the Unique Entity Json and Unique Entity Profile Json. Use these two Json files to learn more about the entity and to help you investigate the alert.

Unique Entity JSON file format