Microsoft Defender XDR
General

Manage analytics rule correlation settings in Microsoft Defender XDR

In brief

The page now explicitly names the Incident correlation default setting and clarifies that individual analytics rules can override it with the `#INC_CORR#` description tag. Microsoft Sentinel Contributor role wording and page metadata were also updated.

What Defender admins need to know

Administrators get clearer guidance for controlling which analytics rules participate in incident correlation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage analytics rule correlation settings in Microsoft Defender XDR

To manage analytics rule exclusions from correlation, you need the following permissions:

Microsoft Sentinel Contributor Users with thisThis Azure role canlets you manage Microsoft Sentinel SIEM workspace data, including alerts and detections.

How exclusion works

:::image type="content" source="./media/exclude-analytics-rules-correlation/correlation-default-setting.png" alt-text="Screenshot of the Incident correlation default setting toggle switch." lightbox="./media/exclude-analytics-rules-correlation/correlation-default-setting.png":::

You can override the default behavior for individual rules by adding a description tag. When you turn off the incident correlation behavior default setting, Microsoft Defender excludes all analytics rules from correlation unless you explicitly include a rule by adding the #INC_CORR# (include correlation) tag to its description. When you turn on the Incident correlation default setting, Defender correlates all analytics rules unless you explicitly configure to exclude them by adding the #DONT_CORR# tag.

Manage a rule's correlation behavior using the UI