Microsoft Defender for Identity
Identity protection

Security alerts

In brief

The page now explains that sensor versions can contribute to either classic or Defender-format alerts. During the transition, detections may appear in both lists with different names; Detection source identifies the format. Tuning and exclusions are format-specific.

What Defender admins need to know

Use Detection source when investigating duplicate or differently named alerts, and apply tuning through the settings appropriate to the alert format.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Identity alerts currently appear in two different layouts in the Microsoft Defender portal. While the alert views may show different information, all alerts are based on detections from Defender for Identity sensors. The differences in layout and information shown are part of an ongoing transition to a unified alerting experience across Microsoft Defender products.

To learn more about how to understand the structure, and common components of all Defender for Identity security alerts, see View and manage alerts.

For information about True positive (TP), Benign true positive (B-TP), and False positive (FP), see security alert classifications.