You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: Learn how to fine-tune the Microsoft Defender for Cloud security alert emails.
4
-
ms.topic: quickstart
2
+
title: Configure email notifications for alerts and attack paths
3
+
description: Learn how to fine-tune the Microsoft Defender for Cloud security alert emails to ensure the right people receive timely notifications.
4
+
ms.topic: how-to
5
5
ms.author: dacurwin
6
6
author: dcurwin
7
-
ms.date: 02/25/2024
7
+
ms.date: 05/19/2024
8
8
ms.custom: mode-other
9
+
#customer intent: As a user, I want to learn how to customize email notifications for alerts and attack paths in Microsoft Defender for Cloud.
9
10
---
10
-
# Quickstart: configure email notifications for security alerts
11
11
12
-
Security alerts need to reach the right people in your organization. By default, Microsoft Defender for Cloud emails subscription owners whenever a high-severity alert is triggered for their subscription. This page explains how to customize these notifications.
12
+
# Configure email notifications for alerts and attack paths
13
13
14
-
Use Defender for Cloud's **Email notifications** settings page to define preferences for notification emails including:
14
+
Microsoft Defender for Cloud allows you to configure email notifications for alerts and attack paths. Configuring email notifications allows for the delivery of timely notifications to the appropriate recipients. By modifying the email notification settings, preferences can be defined for the severity levels of alerts and the risk level of attack paths that trigger notifications. By default, subscription owners receive email notifications for high-severity alerts and attack paths.
15
+
16
+
Defender for Cloud's **Email notifications** settings page allows you to define preferences for notification emails including:
15
17
16
18
-***who* should be notified** - Emails can be sent to select individuals or to anyone with a specified Azure role for a subscription.
17
19
-***what* they should be notified about** - Modify the severity levels for which Defender for Cloud should send out notifications.
18
20
19
-
To avoid alert fatigue, Defender for Cloud limits the volume of outgoing emails. For each email address, Defender for Cloud sends:
21
+
:::image type="content" source="./media/configure-email-notifications/email-notification-settings.png" alt-text="Screenshot showing how to configure the details of the contact who is to receive emails about alerts and attack paths." lightbox="media/configure-email-notifications/email-notification-settings.png":::
20
22
21
-
- approximately **four emails per day** for **high-severity** alerts
22
-
- approximately **two emails per day** for **medium-severity** alerts
23
-
- approximately **one email per day** for **low-severity** alerts
23
+
## Email frequency
24
24
25
-
:::image type="content" source="./media/configure-email-notifications/email-notification-settings.png" alt-text="Configuring the details of the contact who is to receive emails about security alerts." lightbox="media/configure-email-notifications/email-notification-settings.png":::
25
+
To avoid alert fatigue, Defender for Cloud limits the volume of outgoing emails. For each email address, Defender for Cloud sends:
26
+
27
+
|Alert type | Severity/Risk level | Email volume |
28
+
|--|--|--|
29
+
| Alert | High | Four emails per day |
30
+
| Alert | Medium | Two emails per day |
31
+
| Alert | Low | One email per day |
32
+
| Attack path | Critical | One email per 30 minutes |
33
+
| Attack path | High | One email per hour |
34
+
| Attack path | Medium | One email per two hours |
35
+
| Attack path | Low | One email per three hours |
26
36
27
37
## Availability
28
38
29
-
|Aspect|Details|
30
-
|----|:----|
31
-
|Release state:|General availability (GA)|
32
-
|Pricing:|Email notifications are free; for security alerts, enable the enhanced security plans ([plan pricing](https://azure.microsoft.com/pricing/details/defender-for-cloud/)) |
33
-
|Required roles and permissions:|**Security Admin**<br>**Subscription Owner**<br>**Contributor**|
34
-
|Clouds:|:::image type="icon" source="./media/icons/yes-icon.png"::: Commercial clouds<br>:::image type="icon" source="./media/icons/yes-icon.png"::: National (Azure Government, Microsoft Azure operated by 21Vianet)|
39
+
Required roles and permissions: Security Admin, Subscription Owner or Contributor.
35
40
36
-
## Customize the security alerts email notifications via the portal<aname="email"></a>
41
+
## Customize the email notifications in the portal
37
42
38
43
You can send email notifications to individuals or to all users with specific Azure roles.
39
44
40
-
1. From Defender for Cloud's **Environment settings** area, select the relevant subscription, and open **Email notifications**.
45
+
1. Sign in to the [Azure portal](https://portal.azure.com/).
46
+
47
+
1. Navigate to **Microsoft Defender for Cloud** > **Environment settings**.
48
+
49
+
1. Select the relevant subscription.
50
+
51
+
1. Select **email notifications**.
41
52
42
53
1. Define the recipients for your notifications with one or both of these options:
43
54
44
55
- From the dropdown list, select from the available roles.
45
56
- Enter specific email addresses separated by commas. There's no limit to the number of email addresses that you can enter.
46
57
47
-
1. To apply the security contact information to your subscription, select **Save**.
58
+
1. Select the notification types:
59
+
60
+
-**Notify about alerts with the following severity (or higher)** and select a severity level.
61
+
-**Notify about attack paths with the following risk level (or higher)** and select a risk level.
48
62
49
-
## Customize the alerts email notifications through the API
63
+
1. Select **Save**.
64
+
65
+
## Customize the email notifications with an API
50
66
51
67
You can also manage your email notifications through the supplied REST API. For full details, see the [SecurityContacts API documentation](/rest/api/defenderforcloud/security-contacts).
To learn more about security alerts, see the following pages:
90
+
## Related content
77
91
78
92
-[Security alerts - a reference guide](alerts-reference.md) - Learn about the security alerts you might see in Microsoft Defender for Cloud's Threat Protection module.
79
93
-[Manage and respond to security alerts in Microsoft Defender for Cloud](managing-and-responding-alerts.yml) - Learn how to manage and respond to security alerts.
94
+
-[Identify and remediate attack paths](how-to-manage-attack-path.md).
95
+
-[Investigating risk with security explorer/attack paths](concept-attack-path.md)
80
96
-[Workflow automation](workflow-automation.yml) - Automate responses to alerts with custom notification logic.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/permissions.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: User roles and permissions
3
3
description: This article explains how Microsoft Defender for Cloud uses role-based access control to assign permissions to users and identify the permitted actions for each role.
4
4
ms.topic: limits-and-quotas
5
-
ms.date: 10/09/2023
5
+
ms.date: 05/12/2024
6
6
---
7
7
8
8
# User roles and permissions
@@ -32,6 +32,7 @@ The following table displays roles and allowed actions in Defender for Cloud.
32
32
| Apply security recommendations for a resource</br> (and use [Fix](implement-security-recommendations.md)) | - | - | ✔ | ✔ | ✔ |
The specific role required to deploy monitoring components depends on the extension you're deploying. Learn more about [monitoring components](monitoring-components.md).
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+13-4Lines changed: 13 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Release notes
3
3
description: This page is updated frequently with the latest updates in Defender for Cloud.
4
4
ms.topic: overview
5
-
ms.date: 05/20/2024
5
+
ms.date: 05/22/2024
6
6
---
7
7
8
8
# What's new in Microsoft Defender for Cloud?
@@ -24,19 +24,28 @@ If you're looking for items older than six months, you can find them in the [Arc
24
24
25
25
|Date | Update |
26
26
|--|--|
27
+
| May 22 |[Configure email notifications for attack paths](#configure-email-notifications-for-attack-paths)|
27
28
| May 21 |[Advanced hunting in Microsoft Defender XDR now includes Defender for Cloud alerts and incidents](#advanced-hunting-in-microsoft-defender-xdr-now-includes-defender-for-cloud-alerts-and-incidents)|
28
29
| May 9 |[Checkov integration for IaC scanning in Defender for Cloud (Preview)](#checkov-integration-for-iac-scanning-in-defender-for-cloud-preview)|
29
-
| May 7 |[General availability of permissions management in Defender for Cloud](#general-availability-of-permissions-management-in-defender-for-cloud)|
30
30
| May 6 |[AI multicloud security posture management is publicly available for Azure and AWS](#ai-multicloud-security-posture-management-is-publicly-available-for-azure-and-aws)|
31
-
| May 6 |[Limited public preview of threat protection for AI workloads in Azure](#limited-public-preview-of-threat-protection-for-ai-workloads-in-azure)|
32
31
| May 2 |[Updated security policy management is now generally available](#updated-security-policy-management-is-now-generally-available)|
33
32
| May 1 |[Defender for open-source databases is now available on AWS for Amazon instances (Preview)](#defender-for-open-source-databases-is-now-available-on-aws-for-amazon-instances-preview)|
34
33
34
+
### Configure email notifications for attack paths
35
+
36
+
May 22, 2024
37
+
38
+
You can now configure email notifications for attack paths in Defender for Cloud. This feature allows you to receive email notifications when an attack path is detected with a specified risk level or higher.
39
+
40
+
Learn how to [configure email notifications](configure-email-notifications.md).
41
+
35
42
### Advanced hunting in Microsoft Defender XDR now includes Defender for Cloud alerts and incidents
36
43
44
+
May 21, 2024
45
+
37
46
Defender for Cloud's alerts and incidents are now integrated with Microsoft Defender XDR. This integration allows security teams to access Defender for Cloud alerts and incidents within the Microsoft Defender Portal. This integration provides richer context to investigations that span cloud resources, devices, and identities.
38
47
39
-
Learn more about about the [advanced hunting in XDR integration](concept-integration-365.md#advanced-hunting-in-xdr).
48
+
Learn more about the [advanced hunting in XDR integration](concept-integration-365.md#advanced-hunting-in-xdr).
40
49
41
50
### Checkov integration for IaC scanning in Defender for Cloud (Preview)
0 commit comments