Skip to content

Commit c2bd287

Browse files
committed
updates
1 parent a4e45e2 commit c2bd287

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

defender-xdr/irm-investigate-alerts-defender.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -131,9 +131,9 @@ The following alert classification mapping is used to sync the alert classificat
131131

132132
|Microsoft Defender alert classification|Microsoft Purview Insider Risk Management alert classification|
133133
|:---|:---|
134-
|True positive|Confirmed|
135-
|Information, expected activity (benign positive)|Dismissed|
136-
|False positive|Dismissed|
134+
|True positive </br> Includes multi-staged attack, phishing, etc.|Confirmed|
135+
|Information, expected activity (benign positive) </br> Includes Ssecurity testing, confirmed activity, etc.|Dismissed|
136+
|False positive </br> Includes not malicious, not enough data to validate, etc.|Dismissed|
137137

138138
For more information about alert statuses and classifications in Microsoft Defender XDR, see [Manage alerts in Microsoft Defender](investigate-alerts.md#manage-alerts).
139139

0 commit comments

Comments
 (0)