Skip to content

Commit bdbfc64

Browse files
Learn Editor: Update dlp-investigate-alerts-defender.md
1 parent c35b284 commit bdbfc64

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

defender-xdr/dlp-investigate-alerts-defender.md

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -83,8 +83,14 @@ It's best practice to only grant minimal permissions to alerts in the Microsoft
8383

8484
1. Search for the DLP policy name of the alerts and incidents you're interested in.
8585

86-
1. To view the incident summary page, select the incident from the queue. Similarly, select the alert to view the DLP alert page.
87-
86+
1. To view the incident summary page, select the incident from the queue. Similarly, select the alert to view the DLP alert page. Note: Select **Summarize.** This causes the Security Copilot to generate a summary of the alert. The alert summary will contain the:
87+
88+
alert severity
89+
alert title
90+
the name of the policy that was matched
91+
the name file involved and a link to the file
92+
alert status
93+
the email address of the user who performed the action that matched the policy
8894
1. View the **Alert story** for details about policy and the sensitive information types detected in the alert. Select the event in the **Related Events** section to see the user activity details.
8995

9096
1. View the matched sensitive content in the **Sensitive info types** tab and the file content in the **Source** tab if you have the required permission (See details <a href="/microsoft-365/compliance/dlp-alerts-dashboard-get-started#roles" target="_blank">here</a>).

0 commit comments

Comments
 (0)