Skip to content

Commit d554595

Browse files
authored
Merge pull request #1677 from dhairyya/main
AIR wont be triggered
2 parents d5f5ffe + 80b2d39 commit d554595

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

defender-office-365/air-about.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.author: chrisda
77
manager: deniseb
88
audience: ITPro
99
ms.topic: conceptual
10-
ms.date: 06/09/2023
10+
ms.date: 10/22/2024
1111
ms.localizationpriority: medium
1212
search.appverid:
1313
- MET150
@@ -79,7 +79,9 @@ In addition, make sure to review your organization's [alert policies](alert-poli
7979

8080
## Which alert policies trigger automated investigations?
8181

82-
Microsoft 365 provides many built-in alert policies that help identify Exchange admin permissions abuse, malware activity, potential external and internal threats, and information governance risks. Several of the [default alert policies](/purview/alert-policies#default-alert-policies) can trigger automated investigations. The following table describes the alerts that trigger automated investigations, their severity in the Microsoft Defender portal, and how they're generated:
82+
Microsoft 365 provides many built-in alert policies that help identify Exchange admin permissions abuse, malware activity, potential external and internal threats, and information governance risks. Several of the [default alert policies](/purview/alert-policies#default-alert-policies) can trigger automated investigations. If these alerts are disabled or replaced by custom alerts, AIR isn't triggered.
83+
84+
The following table describes the alerts that trigger automated investigations, their severity in the Microsoft Defender portal, and how they're generated:
8385

8486
|Alert|Severity|How the alert is generated|
8587
|---|---|---|

0 commit comments

Comments
 (0)