Security alerts
In brief
The page now explains that sensor versions can contribute to either classic or Defender-format alerts. During the transition, detections may appear in both lists with different names; Detection source identifies the format. Tuning and exclusions are format-specific.
What Defender admins need to know
Use Detection source when investigating duplicate or differently named alerts, and apply tuning through the settings appropriate to the alert format.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Microsoft Defender for Identity alerts currently appear in two different layouts in the Microsoft Defender portal. While the alert views may show different information, all alerts are based on detections from Defender for Identity sensors. The differences in layout and information shown are part of an ongoing transition to a unified alerting experience across Microsoft Defender products.
To learn more about how to understand the structure, and common components of all Defender for Identity security alerts, see View and manage alerts.
For information about True positive (TP), Benign true positive (B-TP), and False positive (FP), see security alert classifications.
@@ -1,7 +1,7 @@ --- title: Security alerts description: This article provides a list of the security alerts issued by Microsoft Defender for Identity.-ms.date: 05/08/2025+ms.date: 07/01/2026 ms.topic: reference ms.reviewer: rlitinsky ---@@ -21,6 +21,13 @@ Alerts originating from Defender for Identity trigger [Microsoft Defender automa Microsoft Defender for Identity alerts currently appear in two different layouts in the Microsoft Defender portal. While the alert views may show different information, all alerts are based on detections from Defender for Identity sensors. The differences in layout and information shown are part of an ongoing transition to a unified alerting experience across Microsoft Defender products. +> [!NOTE]+> Classic and Defender-format alerts aren't tied to sensor version. A v2.x or v3.x sensor can contribute data to alerts in either format, depending on the **Detection source** shown on the alert.+>+> During the transition to the Defender-format alert experience, some detections might appear in both the classic alert list and the Defender-format alert list with different names. Use **Detection source** to confirm which format generated the alert.+>+> Tuning is format-specific. Exclusions configured under **Settings** > **Identities** > **Excluded entities** apply to Defender for Identity detection exclusions. Defender-format alerts should be tuned with [Microsoft Defender alert tuning rules](/microsoft-365/security/defender/investigate-alerts#tune-an-alert).+ To learn more about how to understand the structure, and common components of all Defender for Identity security alerts, see [View and manage alerts](understanding-security-alerts.md). For information about **True positive (TP)**, **Benign true positive (B-TP)**, and **False positive (FP)**, see [security alert classifications](understanding-security-alerts.md#classify-security-alerts). 