Microsoft Defender XDR
General

M365d Notifications Incidents

In brief

The documentation now consistently refers to email notifications, clarifies that severity filters can be set for each service or detection source, and refines the instructions for creating rules and opening incidents from notification emails.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Prerelease]

You can set up email notifications for your staff to get notified about new incidents or updates to existing incidents. You can choose to get email notifications based on:

  • Alert severity
  • Alert sources You can easily select specific service sources that you want to get email notifications for.

Get more granularity with specific detection sources: You can get email notifications only for a specific detection source.

Set the severity per detection or service source: You can choose to get email notifications only on specific severities perfor each service source or detection source. For example, you can get notified for Medium and High alerts for EDR and all severities for Microsoft Defender Experts.

The email notification contains important details about the incident like the incident name, severity, and categories, among others. You can also go directly to the incident and start your analysis right away. For more information, see Investigate incidents.

:::image type="content" source="media/m365d-notifications-incidents/incident-notif-settings-small.png" alt-text="Screenshot of the Notification settings page for incident email notifications in the Microsoft Defender portal." lightbox="media/m365d-notifications-incidents/incident-notif-settings.png":::
  1. Select Next. On the Recipients page, add the email addresses where the incident notifications are to be sent. Select Add after typing each new email address. To test notifications and ensure that the recipients receive them in the inboxes, select Send test email.
  2. Select Next. On the Review rule page, review the settings of the rule, and then select Create rule. Recipients will start receiving incident notifications through email based on the settings.rule settings you configured.

To edit an existing rule, select it from the list of rules. On the pane with the rule name, select Edit rule and make your changes on the Basics, Notification settings, and Recipients pages.

To delete a rule, select it from the list of rules. On the pane with the rule name, select Delete.

Once you get thereceive an incident email notification, you can go directly to the incident and start your investigation right away. For more information on investigating incidents, see Investigate incidents.

Next steps