Skip to content

Commit 9f88d67

Browse files
committed
Update manage-suppression-rules.md
1 parent 97b55c1 commit 9f88d67

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

defender-endpoint/manage-suppression-rules.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ ms.collection:
1313
ms.topic: conceptual
1414
ms.subservice: edr
1515
search.appverid: met150
16-
ms.date: 12/18/2020
16+
ms.date: 06/25/2024
1717
---
1818

1919
# Manage suppression rules
@@ -28,13 +28,14 @@ ms.date: 12/18/2020
2828

2929
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-wdatp-exposedapis-abovefoldlink)
3030
31-
3231
There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts.md).
3332

3433
You can view a list of all the suppression rules and manage them in one place. You can also turn an alert suppression rule on or off.
3534

35+
> [!IMPORTANT]
36+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
3637
37-
1. Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
38+
1. Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global Administrator role assigned.
3839

3940
2. In the navigation pane, select **Settings** \> **Endpoints** \> **Rules** \> **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
4041

@@ -47,9 +48,10 @@ You can view a list of all the suppression rules and manage them in one place. Y
4748

4849
1. In the navigation pane, select **Settings** \> **Endpoints** \> **Rules** \> **Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
4950

50-
2. Click on a rule name. Details of the rule is displayed. You'll see the rule details such as status, scope, action, number of matching alerts, created by, and date when the rule was created. You can also view associated alerts and the rule conditions.
51+
2. Select a rule name. Details of the rule is displayed. You'll see the rule details such as status, scope, action, number of matching alerts, created by, and date when the rule was created. You can also view associated alerts and the rule conditions.
5152

5253
## Related topics
5354

5455
- [Manage alerts](manage-alerts.md)
56+
5557
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)