You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/configure-email-notifications.md
+4-3Lines changed: 4 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier2
13
13
ms.topic: conceptual
14
14
search.appverid: met150
15
-
ms.date: 07/08/2024
15
+
ms.date: 01/17/2025
16
16
---
17
17
18
18
# Configure alert notifications
@@ -43,9 +43,10 @@ If you're using role-based access control (RBAC), recipients will only receive n
43
43
The email notification includes basic information about the alert and a link to the portal where you can do further investigation.
44
44
45
45
## Create rules for alert notifications
46
+
46
47
You can create rules that determine the devices and alert severities to send email notifications for and the notification recipients.
47
48
48
-
1. Go to [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in using an account with the Security administrator or Global administrator role assigned.
49
+
1. Go to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in using an account with the Security administrator or Global administrator role assigned.
49
50
50
51
2. In the navigation pane, select **Settings**\>**Endpoints**\>**General**\>**Email notifications**.
51
52
@@ -102,5 +103,5 @@ This section lists various issues that you may encounter when using email notifi
102
103
-[Update data retention settings](/defender-endpoint/preferences-setup)
Copy file name to clipboardExpand all lines: defender-xdr/faq-managed-response.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.custom:
16
16
- cx-ti
17
17
- cx-dex
18
18
search.appverid: met150
19
-
ms.date: 01/16/2025
19
+
ms.date: 01/17/2025
20
20
---
21
21
22
22
# Understanding Managed response
@@ -30,7 +30,7 @@ The following section lists down questions you or your SOC team might have regar
30
30
| Questions | Answers |
31
31
|---------|---------|
32
32
|**What is Managed response?**| Microsoft Defender Experts for XDR offers **Managed response** where our experts manage the entire remediation process for incidents that require them. This process includes investigating the incident to identify the root cause, determining the required response actions, and taking those actions on your behalf.|
33
-
|**What actions are in scope for Managed response?**| All actions found below are in scope for Managed response for any device and user that isn't excluded.<br><br>*For devices**(Available now)*<ul><li>Isolate machine<br><li>Release machine from isolation<br><li>Stop and quarantine file<br><li>Restrict app execution<br><li>Remove app restriction</ul><br>*For users (Coming soon)*<ul><li>Disable user<br><li>Enable user<br><li>Revoke refresh token<br><li>Soft delete emails</ul> |
33
+
|**What actions are in scope for Managed response?**| All actions found below are in scope for Managed response for any device and user that isn't excluded.<br><br>*For devices**(Available now)*<ul><li>Isolate machine<br><li>Release machine from isolation<br><li>Stop and quarantine file<br><li>Restrict app execution<br><li>Remove app restriction</ul><br>*For users (Available now)*<ul><li>Disable user<br><li>Enable user</ul><br>*For users (Coming soon)*<ul><li>Revoke refresh token<br><li>Soft delete emails</ul> |
34
34
|**Can I customize the extent of Managed response?**| You can configure the extent to which our experts do Managed response actions on your behalf by excluding certain devices and users (individually or by groups) either during onboarding or later by modifying your service's settings. [Read more about excluding device groups](get-started-xdr.md#exclude-devices-and-users-from-remediation)|
35
35
|**What support do Defender Experts offer for excluded assets?**| If our experts determine that you need to perform response actions on excluded devices or users, we notify you through various customizable methods and direct you to your Microsoft Defender XDR portal. From your portal, you can then view a detailed summary of our investigation process and the required response actions in the portal and perform these required actions directly. Similar capabilities are also available through Defender APIs, in case you prefer using a security information and event management (SIEM), IT service management (ITSM), or any other third-party tool. |
36
36
|**How am I going to be informed about the response actions?**| Response actions that our experts have completed on your behalf and any pending ones that you need to perform on your excluded assets are displayed in the **Managed response** panel in your Defender portal's **Incidents** page. <br><br>In addition, you'll also receive an email containing a link to the incident and instructions to view the Managed response in the portal. Moreover, if you have integration with Microsoft Sentinel or APIs, you'll also be notified within those tools by looking for Defender Experts statuses. For more information, see [FAQs related to Microsoft Defender Experts for XDR incident notifications](faq-incident-notifications-xdr.md).|
You can set up Microsoft Defender XDR to notify your staff with an email about new incidents or updates to existing incidents. You can choose to get notifications based on:
30
+
You can set up email notifications for your staff to get notified about new incidents or updates to existing incidents. You can choose to get notifications based on:
33
31
34
32
- Alert severity
35
33
- Alert sources
@@ -59,32 +57,28 @@ Likewise, if your organization is using role-based access control (RBAC), you ca
59
57
60
58
Follow these steps to create a new rule and customize email notification settings.
61
59
62
-
1. Go to [Microsoft Defender XDR](https://security.microsoft.com) in the navigation pane, select **Settings > Microsoft Defender XDR > Incident email notifications**.
63
-
2.Select **Add item**.
60
+
1. Go to the [Microsoft Defender portal](https://security.microsoft.com). In the navigation pane, select **Settings > Microsoft Defender XDR**, then select **Email notifications** under General.
61
+
2.In the **Incidents** tab, select **Add incident notification rule**.
64
62
3. On the **Basics** page, type the rule name and a description, and then select **Next**.
65
63
4. On the **Notification settings** page, configure:
66
-
-**Alert severity** - Choose the alert severities that will trigger an incident notification. For example, if you only want to be informed about high-severity incidents, select **High**.
64
+
-**Alert severity** - Choose the alert severities that triggers an incident notification. For example, if you only want to be informed about high-severity incidents, select **High**.
67
65
-**Device group scope** - You can specify all device groups or select from the list of device groups in your tenant.
68
66
-**Send only one notification per incident** - Select if you want one notification per incident.
69
67
-**Include organization name in the email** - Select if you want your organization name to appear in the email notification.
70
68
-**Include tenant-specific portal link** - Select if you want to add a link with the tenant ID in the email notification for access to a specific Microsoft 365 tenant.
71
69
72
-
:::image type="content" source="/defender/media/get-incident-notifications/incidents-email-notification-settings.png" alt-text="Screenshot of the Notification settings page for incident email notifications in the Microsoft Defender portal." lightbox="/defender/media/get-incident-notifications/incidents-email-notification-settings.png":::
70
+
:::image type="content" source="/defender/media/get-incident-notifications/incident-notif-settings-small.png" alt-text="Screenshot of the Notification settings page for incident email notifications in the Microsoft Defender portal." lightbox="/defender/media/get-incident-notifications/incident-notif-settings.png":::
73
71
74
-
5. Select **Next**. On the **Recipients** page, add the email addresses that will receive the incident notifications. Select **Add** after typing each new email address. To test notifications and ensure that the recipients receive them in the inboxes, select **Send test email**.
72
+
5. Select **Next**. On the **Recipients** page, add the email addresses where the incident notifications are to be sent. Select **Add** after typing each new email address. To test notifications and ensure that the recipients receive them in the inboxes, select **Send test email**.
75
73
6. Select **Next**. On the **Review rule** page, review the settings of the rule, and then select **Create rule**. Recipients will start receiving incident notifications through email based on the settings.
76
74
77
75
To edit an existing rule, select it from the list of rules. On the pane with the rule name, select **Edit rule** and make your changes on the **Basics**, **Notification settings**, and **Recipients** pages.
78
76
79
77
To delete a rule, select it from the list of rules. On the pane with the rule name, select **Delete**.
80
78
81
-
Once you get the notification, you can go directly to the incident and start your investigation right away. For more information on investigating incidents, see [Investigate incidents in Microsoft Defender XDR](investigate-incidents.md).
79
+
Once you get the notification, you can go directly to the incident and start your investigation right away. For more information on investigating incidents, see [Investigate incidents](investigate-incidents.md).
82
80
83
81
## Next steps
84
82
85
83
-[Get email notifications on response actions](m365d-response-actions-notifications.md)
86
84
-[Get email notifications about new reports in Threat analytics](m365d-threat-analytics-notifications.md)
87
-
88
-
## See also
89
-
90
-
-[Investigate incidents in Microsoft Defender XDR](investigate-incidents.md)
You can set up Microsoft Defender XDR to notify you through email about manual or automated response actions.
30
+
You can set up email notifications in the Microsoft Defender portal to notify you about manual or automated response actions.
33
31
34
-
[Manual response actions](respond-first-incident-remediate.md#manual-remediation) are actions that security teams can use to stop threats or aid in investigation of attacks. These actions vary depending on the Defender workload enabled in your environment.
32
+
Manual response actions are actions that security teams can use to stop threats or aid in investigation of attacks. These actions vary depending on the Defender workload enabled in your environment.
35
33
36
-
[Automated response actions](respond-first-incident-remediate.md#automatic-remediation), on the other hand, are capabilities in Microsoft Defender XDR that scale investigation and resolution to threats automatically. Automated remediation capabilities consist of [automatic attack disruption](automatic-attack-disruption.md) and [automated investigation and response](m365d-autoir.md).
34
+
Automated response actions are capabilities in Microsoft Defender XDR that scale investigation and resolution to threats automatically. Automated remediation capabilities consist of [automatic attack disruption](automatic-attack-disruption.md) and [automated investigation and response](m365d-autoir.md).
37
35
38
36
> [!NOTE]
39
37
> You need the **Manage security settings** permission to configure email notification settings. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications. Likewise, if your organization is using [role-based access control (RBAC)](manage-rbac.md), you can only create, edit, delete, and receive notifications based on device groups that you are allowed to manage.
@@ -48,7 +46,7 @@ You can set up Microsoft Defender XDR to notify you through email about manual o
48
46
49
47
To create a rule for email notifications, perform the following steps:
50
48
51
-
1. In the navigation pane of Microsoft Defender XDR, select **Settings > Microsoft Defender XDR**. Under **General**, select **Email notifications**. Go to the **Actions** tab.
49
+
1. In the navigation pane of the Microsoft Defender portal, select **Settings > Microsoft Defender XDR**. Under **General**, select **Email notifications**. Go to the **Actions** tab.
52
50
:::image type="content" source="/defender/media/m35d-response-actions-notifications/fig1-response-notifications.png" alt-text="Actions tab in the Microsoft Defender XDR Settings page" lightbox="/defender/media/m35d-response-actions-notifications/fig1-response-notifications.png":::
53
51
2. Select **Add notification rule**. Add a rule name and description under Basics. Both Name and Description fields accept letters, numbers, and spaces only.
54
52
:::image type="content" source="/defender/media/m35d-response-actions-notifications/fig2-response-notifications.png" alt-text="Basics section of the add notification rule" lightbox="/defender/media/m35d-response-actions-notifications/fig2-response-notifications.png":::
0 commit comments