Skip to content

Commit b75f08f

Browse files
authored
Merge pull request #3119 from shivanimahapatro/docs-editor/dlp-investigate-alerts-defende-1741818536
Update dlp-investigate-alerts-defender.md
2 parents 1f1bb29 + 8670ce1 commit b75f08f

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

defender-xdr/dlp-investigate-alerts-defender.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,14 @@ It's best practice to only grant minimal permissions to alerts in the Microsoft
8383

8484
1. Search for the DLP policy name of the alerts and incidents you're interested in.
8585

86-
1. To view the incident summary page, select the incident from the queue. Similarly, select the alert to view the DLP alert page.
86+
1. To view the incident summary page, select the incident from the queue. Similarly, select the alert to view the DLP alert page. Select **Summarize** (preview) for Security Copilot to generate a summary of the alert. The alert summary will contain the:
87+
88+
- alert severity
89+
- alert title
90+
- the name of the policy that was matched
91+
- the name file involved and a link to the file
92+
- alert status
93+
- the email address of the user who performed the action that matched the policy
8794

8895
1. View the **Alert story** for details about policy and the sensitive information types detected in the alert. Select the event in the **Related Events** section to see the user activity details.
8996

0 commit comments

Comments
 (0)