You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/configure-email-notifications.md
+4-3Lines changed: 4 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier2
13
13
ms.topic: conceptual
14
14
search.appverid: met150
15
-
ms.date: 07/08/2024
15
+
ms.date: 01/17/2025
16
16
---
17
17
18
18
# Configure alert notifications
@@ -43,9 +43,10 @@ If you're using role-based access control (RBAC), recipients will only receive n
43
43
The email notification includes basic information about the alert and a link to the portal where you can do further investigation.
44
44
45
45
## Create rules for alert notifications
46
+
46
47
You can create rules that determine the devices and alert severities to send email notifications for and the notification recipients.
47
48
48
-
1. Go to [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in using an account with the Security administrator or Global administrator role assigned.
49
+
1. Go to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in using an account with the Security administrator or Global administrator role assigned.
49
50
50
51
2. In the navigation pane, select **Settings**\>**Endpoints**\>**General**\>**Email notifications**.
51
52
@@ -102,5 +103,5 @@ This section lists various issues that you may encounter when using email notifi
102
103
-[Update data retention settings](/defender-endpoint/preferences-setup)
You can set up Microsoft Defender XDR to notify your staff with an email about new incidents or updates to existing incidents. You can choose to get notifications based on:
30
+
You can set up email notifications for your staff to get notified about new incidents or updates to existing incidents. You can choose to get notifications based on:
33
31
34
32
- Alert severity
35
33
- Alert sources
@@ -59,32 +57,28 @@ Likewise, if your organization is using role-based access control (RBAC), you ca
59
57
60
58
Follow these steps to create a new rule and customize email notification settings.
61
59
62
-
1. Go to [Microsoft Defender XDR](https://security.microsoft.com) in the navigation pane, select **Settings > Microsoft Defender XDR > Incident email notifications**.
63
-
2.Select **Add item**.
60
+
1. Go to the [Microsoft Defender portal](https://security.microsoft.com). In the navigation pane, select **Settings > Microsoft Defender XDR**, then select **Email notifications** under General.
61
+
2.In the **Incidents** tab, select **Add incident notification rule**.
64
62
3. On the **Basics** page, type the rule name and a description, and then select **Next**.
65
63
4. On the **Notification settings** page, configure:
66
-
-**Alert severity** - Choose the alert severities that will trigger an incident notification. For example, if you only want to be informed about high-severity incidents, select **High**.
64
+
-**Alert severity** - Choose the alert severities that triggers an incident notification. For example, if you only want to be informed about high-severity incidents, select **High**.
67
65
-**Device group scope** - You can specify all device groups or select from the list of device groups in your tenant.
68
66
-**Send only one notification per incident** - Select if you want one notification per incident.
69
67
-**Include organization name in the email** - Select if you want your organization name to appear in the email notification.
70
68
-**Include tenant-specific portal link** - Select if you want to add a link with the tenant ID in the email notification for access to a specific Microsoft 365 tenant.
71
69
72
-
:::image type="content" source="/defender/media/get-incident-notifications/incidents-email-notification-settings.png" alt-text="Screenshot of the Notification settings page for incident email notifications in the Microsoft Defender portal." lightbox="/defender/media/get-incident-notifications/incidents-email-notification-settings.png":::
70
+
:::image type="content" source="/defender/media/get-incident-notifications/incident-notif-settings-small.png" alt-text="Screenshot of the Notification settings page for incident email notifications in the Microsoft Defender portal." lightbox="/defender/media/get-incident-notifications/incident-notif-settings.png":::
73
71
74
-
5. Select **Next**. On the **Recipients** page, add the email addresses that will receive the incident notifications. Select **Add** after typing each new email address. To test notifications and ensure that the recipients receive them in the inboxes, select **Send test email**.
72
+
5. Select **Next**. On the **Recipients** page, add the email addresses where the incident notifications are to be sent. Select **Add** after typing each new email address. To test notifications and ensure that the recipients receive them in the inboxes, select **Send test email**.
75
73
6. Select **Next**. On the **Review rule** page, review the settings of the rule, and then select **Create rule**. Recipients will start receiving incident notifications through email based on the settings.
76
74
77
75
To edit an existing rule, select it from the list of rules. On the pane with the rule name, select **Edit rule** and make your changes on the **Basics**, **Notification settings**, and **Recipients** pages.
78
76
79
77
To delete a rule, select it from the list of rules. On the pane with the rule name, select **Delete**.
80
78
81
-
Once you get the notification, you can go directly to the incident and start your investigation right away. For more information on investigating incidents, see [Investigate incidents in Microsoft Defender XDR](investigate-incidents.md).
79
+
Once you get the notification, you can go directly to the incident and start your investigation right away. For more information on investigating incidents, see [Investigate incidents](investigate-incidents.md).
82
80
83
81
## Next steps
84
82
85
83
-[Get email notifications on response actions](m365d-response-actions-notifications.md)
86
84
-[Get email notifications about new reports in Threat analytics](m365d-threat-analytics-notifications.md)
87
-
88
-
## See also
89
-
90
-
-[Investigate incidents in Microsoft Defender XDR](investigate-incidents.md)
You can set up Microsoft Defender XDR to notify you through email about manual or automated response actions.
30
+
You can set up email notifications in the Microsoft Defender portal to notify you about manual or automated response actions.
33
31
34
-
[Manual response actions](respond-first-incident-remediate.md#manual-remediation) are actions that security teams can use to stop threats or aid in investigation of attacks. These actions vary depending on the Defender workload enabled in your environment.
32
+
Manual response actions are actions that security teams can use to stop threats or aid in investigation of attacks. These actions vary depending on the Defender workload enabled in your environment.
35
33
36
-
[Automated response actions](respond-first-incident-remediate.md#automatic-remediation), on the other hand, are capabilities in Microsoft Defender XDR that scale investigation and resolution to threats automatically. Automated remediation capabilities consist of [automatic attack disruption](automatic-attack-disruption.md) and [automated investigation and response](m365d-autoir.md).
34
+
Automated response actions are capabilities in Microsoft Defender XDR that scale investigation and resolution to threats automatically. Automated remediation capabilities consist of [automatic attack disruption](automatic-attack-disruption.md) and [automated investigation and response](m365d-autoir.md).
37
35
38
36
> [!NOTE]
39
37
> You need the **Manage security settings** permission to configure email notification settings. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications. Likewise, if your organization is using [role-based access control (RBAC)](manage-rbac.md), you can only create, edit, delete, and receive notifications based on device groups that you are allowed to manage.
@@ -48,7 +46,7 @@ You can set up Microsoft Defender XDR to notify you through email about manual o
48
46
49
47
To create a rule for email notifications, perform the following steps:
50
48
51
-
1. In the navigation pane of Microsoft Defender XDR, select **Settings > Microsoft Defender XDR**. Under **General**, select **Email notifications**. Go to the **Actions** tab.
49
+
1. In the navigation pane of the Microsoft Defender portal, select **Settings > Microsoft Defender XDR**. Under **General**, select **Email notifications**. Go to the **Actions** tab.
52
50
:::image type="content" source="/defender/media/m35d-response-actions-notifications/fig1-response-notifications.png" alt-text="Actions tab in the Microsoft Defender XDR Settings page" lightbox="/defender/media/m35d-response-actions-notifications/fig1-response-notifications.png":::
53
51
2. Select **Add notification rule**. Add a rule name and description under Basics. Both Name and Description fields accept letters, numbers, and spaces only.
54
52
:::image type="content" source="/defender/media/m35d-response-actions-notifications/fig2-response-notifications.png" alt-text="Basics section of the add notification rule" lightbox="/defender/media/m35d-response-actions-notifications/fig2-response-notifications.png":::
You can set up email notifications that sends you updates on [threat analytics](threat-analytics.md) reports.
32
30
33
31
## Set up email notifications for report updates
34
32
35
33
To set up email notifications for threat analytics reports, perform the following steps:
36
34
37
-
1. Select **Settings** in the Microsoft Defender XDR sidebar. Select **Microsoft Defender XDR** from the list of settings.
38
-
39
-

40
-
41
-
2. Choose **Email notifications** > **Threat analytics**, and select the button, **+ Create a notification rule**. A flyout will appear.
35
+
1. In the navigation pane of the Microsoft Defender portal, select **Settings > Microsoft Defender XDR**. Under **General**, select **Email notifications**.
42
36
43
-

37
+
2. In the **Threat analytics** tab, select **+ Create a notification rule**. A flyout will appear.
44
38
45
39
3. Follow the steps listed in the flyout. First, give your new rule a name. The description field is optional, but a name is required. You can toggle the rule on or off using the checkbox under the description field.
46
40
47
-
> [!NOTE]
48
-
> The name and description fields for a new notification rule only accept English letters and numbers. They don't accept spaces, dashes, underscores, or any other punctuation.
49
-
50
-

41
+
> [!NOTE]
42
+
> The name and description fields for a new notification rule only accept English letters and numbers. Punctuations like spaces, dashes, underscores, are not supported.
51
43
52
-
4. Choose which kind of reports you want to be notified about. You can choose between being updated about all newly published or updated reports, or only those reports which have a certain tag or type.
44
+

53
45
54
-

46
+
4. Choose the reports you want to be notified about. You can choose to be updated about all newly published or updated reports or only those reports of a certain type or with a specific tag.
55
47
56
-
5. Add at least one recipient to receive the notification emails. You can also use this screen to check how the notifications will be received, by sending a test email.
48
+

57
49
58
-

50
+
5. Add at least one recipient to receive the notification emails. You can also use this screen to send a test email to check the notification settings.
59
51
60
-
6. Review your new rule. If there is anything you would like to change, select the **Edit** button at the end of each subsection. Once your review is complete, select the **Create rule** button.
52
+

61
53
62
-

54
+
6. Review your new rule. If there is anything you would like to change, select **Edit** at the end of each subsection. Once your review is complete, select **Create rule**.
63
55
64
-
7. Congratulations! Your new rule has been successfully created. Select the **Done**button to complete the process and close the flyout.
56
+

65
57
66
-

58
+
7. Select **Done** to complete the process and close the flyout.
67
59
68
-
8. Your new rule will now appear in the list of Threat analytics email notifications.
60
+

69
61
70
-

62
+
Your new rule now appears in the list of Threat analytics email notifications.
0 commit comments