Microsoft Defender for Cloud
Cloud and workloads

Respond to Microsoft Defender for DNS alerts

In brief

The page date and authoring metadata were updated. The unexpected-activity guidance now links to “Mitigate the alert,” and the “Next step” section was renamed “Next steps” with an anchor added.

What Defender admins need to know

Administrators can navigate directly from an alert to the relevant mitigation guidance; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Contact the resource owner to determine whether the behavior was expected or intentional.
  2. If the activity is expected, dismiss the alert.
  3. If the activity is unexpected, treat the resource as potentially compromised and follow the mitigation steps in the next section.Mitigate the alert.

Mitigate the alert

  • Send alerts in real time to Log Analytics or Event Hubs to build automated response processes. For steps, see Configure continuous export.

Next stepsteps

[!div class="nextstepaction"] Manage security alerts