Manage Respond Alerts
In brief
The page now uses clearer wording for filtering, investigating, updating alert statuses, and finding related guidance. It also specifies that remediating an agent-based alert does not remediate its corresponding agentless alert until the next scan.
What Defender admins need to know
Administrators have clearer instructions for investigating alerts and understanding remediation timing.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
ms.date: 05/28/2026 ms.topic: how-to ms.custom:
- msecd-doc-authoring-1013
- sfi-image-nochange
- ge-structured-content-pilot
#customer intent: As a security analyst, I want to manage and respond to security alerts in Defender for Cloud so that I can triage threats and take remediation actions quickly.
Defender for Cloud collects, analyzes, and integrates log data from your Azure, hybrid, and multicloud resources, the network, and connected partner solutions, such as firewalls and endpoint agents. Defender for Cloud uses the log data to detect real threats and reduce false positives. A list of prioritized security alerts is shown in Defender for Cloud along with the information you need to quickly investigate the problem and the steps to take to remediate an attack.
View, investigate, and respond to security alerts in Defender for Cloud
This article shows you how to view and process Defender for Cloud's alerts and protect your resources.
When triaging security alerts, you should prioritize alerts based on their alert severity, addressing higher severity alerts first. Learn more about how alerts are classified.
:::image type="content" source="./media/managing-and-responding-alerts/alerts-adding-filters-small.png" alt-text="Screenshot that shows you how to add filters to the alerts view." lightbox="./media/managing-and-responding-alerts/alerts-adding-filters-large.png":::
The alerts list updates according to the filters selected.you select. For example, you might you want to address security alerts that occurred in the last 24 hours because you're investigating a potential breach in the system.
Investigate a security alert
Select View full details.
The right pane includes the Alert details tab containing further details of the alert to help you investigate the
issue:alert: IP addresses, files, processes, and more.:::image type="content" source="./media/managing-and-responding-alerts/security-center-alert-remediate.png" alt-text="Screenshot that shows the full details page for an alert.":::
:::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Screenshot that shows the options available in the Take action tab.":::
For
further details,more information about the alert, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
Change the status of multiple security alerts at once
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" alt-text="Screenshot of the security alerts status tab.":::
The alerts shown inon the currentSecurity alerts page have their status changed to the selected value.
Respond to a security alert
To learn about alert types, see Security alerts - a reference guide.
For an overview ofinformation about how Defender for Cloud generates alerts,detects and responds to threats, see How Microsoft Defender for Cloud detects and responds to threats.
Review the agentless scan's results
:::image type="content" source="media/managing-and-responding-alerts/agent-and-agentless-results.png" alt-text="Screenshot of the security alerts page that shows the results of both the agent-based and agentless scan results." lightbox="media/managing-and-responding-alerts/agent-and-agentless-results.png":::
Related content
@@ -4,6 +4,7 @@ description: This document helps you to use Microsoft Defender for Cloud capabil ms.date: 05/28/2026 ms.topic: how-to ms.custom:+ - msecd-doc-authoring-1013 - sfi-image-nochange - ge-structured-content-pilot #customer intent: As a security analyst, I want to manage and respond to security alerts in Defender for Cloud so that I can triage threats and take remediation actions quickly.@@ -14,6 +15,8 @@ ai-usage: ai-assisted Defender for Cloud collects, analyzes, and integrates log data from your Azure, hybrid, and multicloud resources, the network, and connected partner solutions, such as firewalls and endpoint agents. Defender for Cloud uses the log data to detect real threats and reduce false positives. A list of prioritized security alerts is shown in Defender for Cloud along with the information you need to quickly investigate the problem and the steps to take to remediate an attack. +## View, investigate, and respond to security alerts in Defender for Cloud+ This article shows you how to view and process Defender for Cloud's alerts and protect your resources. When triaging security alerts, you should prioritize alerts based on their alert severity, addressing higher severity alerts first. Learn more about [how alerts are classified](alerts-overview.md#how-are-alerts-classified).@@ -39,7 +42,7 @@ Follow these steps: :::image type="content" source="./media/managing-and-responding-alerts/alerts-adding-filters-small.png" alt-text="Screenshot that shows you how to add filters to the alerts view." lightbox="./media/managing-and-responding-alerts/alerts-adding-filters-large.png"::: - The list updates according to the filters selected. For example, you might you want to address security alerts that occurred in the last 24 hours because you're investigating a potential breach in the system.+ The alerts list updates according to the filters you select. For example, you might you want to address security alerts that occurred in the last 24 hours because you're investigating a potential breach in the system. ## Investigate a security alert @@ -60,7 +63,7 @@ Each alert contains information regarding the alert that assists you in your inv 1. Select **View full details**. - The right pane includes the **Alert details** tab containing further details of the alert to help you investigate the issue: IP addresses, files, processes, and more.+ The right pane includes the **Alert details** tab containing further details of the alert to help you investigate the alert: IP addresses, files, processes, and more. :::image type="content" source="./media/managing-and-responding-alerts/security-center-alert-remediate.png" alt-text="Screenshot that shows the full details page for an alert."::: @@ -74,7 +77,7 @@ Each alert contains information regarding the alert that assists you in your inv :::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Screenshot that shows the options available in the Take action tab."::: - For further details, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.+ For more information about the alert, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource. ## Change the status of multiple security alerts at once @@ -96,7 +99,7 @@ The alerts list includes checkboxes so you can handle multiple alerts at once. F :::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" alt-text="Screenshot of the security alerts status tab."::: - The alerts shown in the current page have their status changed to the selected value.+ The alerts shown on the Security alerts page have their status changed to the selected value. ## Respond to a security alert @@ -133,9 +136,9 @@ After investigating a security alert, you can respond to the alert from within M > [!TIP] > We review your feedback to improve our algorithms and provide better security alerts. -To learn about the different types of alerts, see [Security alerts - a reference guide](alerts-reference.md).+To learn about alert types, see [Security alerts - a reference guide](alerts-reference.md). -For an overview of how Defender for Cloud generates alerts, see [How Microsoft Defender for Cloud detects and responds to threats](alerts-overview.md).+For information about how Defender for Cloud detects and responds to threats, see [How Microsoft Defender for Cloud detects and responds to threats](alerts-overview.md). ## Review the agentless scan's results @@ -144,7 +147,7 @@ Results for both the agent-based and agentless scanner appear on the Security al :::image type="content" source="media/managing-and-responding-alerts/agent-and-agentless-results.png" alt-text="Screenshot of the security alerts page that shows the results of both the agent-based and agentless scan results." lightbox="media/managing-and-responding-alerts/agent-and-agentless-results.png"::: > [!NOTE]-> Remediating one of these alerts will not remediate the other alert until the next scan is completed.+> Remediating the agent-based alert will not remediate the corresponding agentless alert until the next scan is completed. ## Related content 