Microsoft Defender for Cloud
Cloud and workloads

Manage Respond Alerts

In brief

The page now uses clearer wording for filtering, investigating, updating alert statuses, and finding related guidance. It also specifies that remediating an agent-based alert does not remediate its corresponding agentless alert until the next scan.

What Defender admins need to know

Administrators have clearer instructions for investigating alerts and understanding remediation timing.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.date: 05/28/2026 ms.topic: how-to ms.custom:

  • msecd-doc-authoring-1013
  • sfi-image-nochange
  • ge-structured-content-pilot

#customer intent: As a security analyst, I want to manage and respond to security alerts in Defender for Cloud so that I can triage threats and take remediation actions quickly.

Defender for Cloud collects, analyzes, and integrates log data from your Azure, hybrid, and multicloud resources, the network, and connected partner solutions, such as firewalls and endpoint agents. Defender for Cloud uses the log data to detect real threats and reduce false positives. A list of prioritized security alerts is shown in Defender for Cloud along with the information you need to quickly investigate the problem and the steps to take to remediate an attack.

View, investigate, and respond to security alerts in Defender for Cloud

This article shows you how to view and process Defender for Cloud's alerts and protect your resources.

When triaging security alerts, you should prioritize alerts based on their alert severity, addressing higher severity alerts first. Learn more about how alerts are classified.

:::image type="content" source="./media/managing-and-responding-alerts/alerts-adding-filters-small.png" alt-text="Screenshot that shows you how to add filters to the alerts view." lightbox="./media/managing-and-responding-alerts/alerts-adding-filters-large.png":::

The alerts list updates according to the filters selected.you select. For example, you might you want to address security alerts that occurred in the last 24 hours because you're investigating a potential breach in the system.

Investigate a security alert

  1. Select View full details.

    The right pane includes the Alert details tab containing further details of the alert to help you investigate the issue:alert: IP addresses, files, processes, and more.

    :::image type="content" source="./media/managing-and-responding-alerts/security-center-alert-remediate.png" alt-text="Screenshot that shows the full details page for an alert.":::

    :::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Screenshot that shows the options available in the Take action tab.":::

    For further details,more information about the alert, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.

Change the status of multiple security alerts at once

:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" alt-text="Screenshot of the security alerts status tab.":::

The alerts shown inon the currentSecurity alerts page have their status changed to the selected value.

Respond to a security alert

To learn about alert types, see Security alerts - a reference guide.

For an overview ofinformation about how Defender for Cloud generates alerts,detects and responds to threats, see How Microsoft Defender for Cloud detects and responds to threats.

Review the agentless scan's results

:::image type="content" source="media/managing-and-responding-alerts/agent-and-agentless-results.png" alt-text="Screenshot of the security alerts page that shows the results of both the agent-based and agentless scan results." lightbox="media/managing-and-responding-alerts/agent-and-agentless-results.png":::

Related content