You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/understanding-security-alerts.md
+8-11Lines changed: 8 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,12 +27,9 @@ Alerts from the last seven days are displayed with the following information:
27
27
- First activity
28
28
- Last activity
29
29
30
+
:::image type="content" source="/media/understanding-security-alerts/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
30
31
31
32
32
-
:::image type="content" source="ATPDocs/media/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
33
-
34
-
:::image type="content" source="ATPDocs/media/understanding-security-alerts/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
35
-
36
33
37
34
## Customize the view of the alerts queue
38
35
@@ -74,7 +71,7 @@ The alerts page provides context into the alert, by combining attack signals and
74
71
75
72
To view alerts from both Defender for Identity and Defender XDR, select **Filter**, then under **Service sources** choose **Microsoft Defender for Identity** and **Defender XDR**, and select **Apply**:
76
73
77
-
:::image type="content" source="media/filter-alerts-menu.png" alt-text="Screenshot showing the alerts filter menu per service.":::
74
+
:::image type="content" source="media/understanding-security-alerts/filter-alerts-menu.png" alt-text="Screenshot showing the alerts filter menu per service.":::
78
75
79
76
### Microsoft Defender for Identity alerts
80
77
@@ -90,7 +87,7 @@ At the top of the page, there are sections for the **Accounts**, **Destination H
90
87
- Move alert to another incident
91
88
- Classify an alert
92
89
93
-
:::image type="content" source="media/legacy-mdi-alert-structure.png" alt-text="Screenshot showing the Defender for Identity alert structure." lightbox="media/legacy-mdi-alert-structure.png":::
90
+
:::image type="content" source="media/understanding-security-alerts/legacy-mdi-alert-structure.png" alt-text="Screenshot showing the Defender for Identity alert structure." lightbox="media/legacy-mdi-alert-structure.png":::
94
91
95
92
### Microsoft Defender XDR alerts
96
93
@@ -103,7 +100,7 @@ At the top of the page, there are sections for the **Accounts**, **Destination H
103
100
- Move alert to another incident
104
101
- Classify an alert
105
102
106
-
:::image type="content" source="media/defender-xdr-alert-structure.png" alt-text="Screenshot showing the Defender for XDR alert structure" lightbox="media/defender-xdr-alert-structure.png":::
103
+
:::image type="content" source="media/understanding-security-alerts/defender-xdr-alert-structure.png" alt-text="Screenshot showing the Defender for XDR alert structure" lightbox="media/defender-xdr-alert-structure.png":::
107
104
108
105
## Manage security alerts
109
106
@@ -115,18 +112,18 @@ You can categorize alerts as New, In Progress, or Resolved by changing their sta
115
112
### Move an alert to another incident
116
113
You can create a new incident from the alert or link to an existing incident.
117
114
118
-
:::image type="content" source="media/move-alert-to-other-incident.png" alt-text="Screenshot showing the option to move an alert to another incident.":::
115
+
:::image type="content" source="media/understanding-security-alerts/move-alert-to-other-incident.png" alt-text="Screenshot showing the option to move an alert to another incident.":::
119
116
120
117
### Assign alerts
121
118
If an alert isn't yet assigned, you can select Assign to me to assign the alert to yourself.
122
119
123
-
:::image type="content" source="media/alert-state.png" alt-text="Screenshot showing the Alert state section in the Microsoft Defender portal. The Classification field is marked as “Not Set” with a link to “Set Classification.” The Assigned to field shows “Unassigned” with a link labeled “Assign to me.” This section allows users to manage alert ownership and classification." lightbox="media/alert-state.png":::
120
+
:::image type="content" source="media/understanding-security-alerts/alert-state.png" alt-text="Screenshot showing the Alert state section in the Microsoft Defender portal. The Classification field is marked as “Not Set” with a link to “Set Classification.” The Assigned to field shows “Unassigned” with a link labeled “Assign to me.” This section allows users to manage alert ownership and classification." lightbox="media/alert-state.png":::
124
121
125
122
### Add comments to an alert
126
123
You can add comments to an alert to provide additional context or information. This is useful for sharing insights with your team or documenting your investigation process.
127
124
Whenever a change or comment is made to an alert, it's recorded in the Comments and history section.
128
125
129
-
:::image type="content" source="media/comments-history.png" alt-text="Screenshot showing the Comments & history section in the Microsoft Defender portal. A text box is provided for entering comments." lightbox="media/comments-history.png":::
126
+
:::image type="content" source="media/understanding-security-alerts/comments-history.png" alt-text="Screenshot showing the Comments & history section in the Microsoft Defender portal. A text box is provided for entering comments." lightbox="media/comments-history.png":::
130
127
131
128
### Classify security alerts
132
129
@@ -145,7 +142,7 @@ Following proper investigation, all Defender for Identity security alerts can be
145
142
146
143
-**False positive (FP)**: A false alarm, meaning the activity didn't happen.
147
144
148
-
:::image type="content" source="media/classify-alert.png" alt-text="Screenshot showing a Microsoft Defender alert titled “Suspected brute-force attack (LDAP).” The alert is labeled with severity Medium, status New, and classification Unknown. Below, a classification banner includes a message to classify the alert, with buttons labeled “True alert” and “False alert” for user response." lightbox="media/classify-alert.png":::
145
+
:::image type="content" source="media/understanding-security-alerts/classify-alert.png" alt-text="Screenshot showing a Microsoft Defender alert titled “Suspected brute-force attack (LDAP).” The alert is labeled with severity Medium, status New, and classification Unknown. Below, a classification banner includes a message to classify the alert, with buttons labeled “True alert” and “False alert” for user response." lightbox="media/classify-alert.png":::
149
146
150
147
> [!NOTE]
151
148
> An increase of alerts of the exact same type typically reduces the suspicious/importance level of the alert. For repeated alerts, verify configurations, and use security alert details and definitions to understand exactly what is happening that trigger the repeats.
0 commit comments