Skip to content

Commit fd7ed16

Browse files
authored
Merge pull request #2479 from MicrosoftDocs/public-168
Update investigate-alerts.md
2 parents bd63dee + 467f4e6 commit fd7ed16

File tree

1 file changed

+11
-15
lines changed

1 file changed

+11
-15
lines changed

defender-xdr/investigate-alerts.md

Lines changed: 11 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,24 @@
11
---
22
title: Investigate alerts in Microsoft Defender XDR
33
description: Investigate alerts seen across devices, users, and mailboxes.
4-
keywords: incidents, alerts, investigate, analyze, response, correlation, attack, machines, devices, users, identities, identity, mailbox, email, 365, microsoft, m365
54
ms.service: defender-xdr
6-
ms.mktglfcycl: deploy
7-
ms.sitesec: library
8-
ms.pagetype: security
95
f1.keywords:
10-
- NOCSH
6+
- NOCSH
117
ms.author: diannegali
128
author: diannegali
139
ms.localizationpriority: medium
1410
manager: deniseb
1511
audience: ITPro
1612
ms.collection:
17-
- m365-security
18-
- m365initiative-m365-defender
19-
- tier1
13+
- m365-security
14+
- m365initiative-m365-defender
15+
- tier1
2016
ms.custom: admindeeplinkDEFENDER
2117
ms.topic: conceptual
2218
search.appverid:
23-
- MOE150
24-
- met150
25-
ms.date: 1/17/2025
19+
- MOE150
20+
- met150
21+
ms.date: 01/17/2025
2622
---
2723

2824
# Investigate alerts in Microsoft Defender XDR
@@ -192,10 +188,9 @@ The **Manage alert** pane allows you to view or specify:
192188
- A comment on the alert.
193189

194190
> [!NOTE]
195-
> Around August 29th, 2022, previously supported alert determination values ('Apt' and 'SecurityPersonnel') will be deprecated and no longer available via the API.
196-
197-
> [!NOTE]
198-
> One way of managing alerts it through the use of tags. The tagging capability for Microsoft Defender for Office 365 is incrementally being rolled out and is currently in preview.
191+
> - In August 2022, previously supported alert determination values (`Apt` and `SecurityPersonnel`) were deprecated and are no longer available via the API.
192+
>
193+
> - One way of managing alerts it through the use of tags. The tagging capability for Microsoft Defender for Office 365 is currently in preview, rolling out incrementally.
199194
>
200195
> Currently, modified tag names are only applied to alerts created *after* the update. Alerts that were generated before the modification will not reflect the updated tag name.
201196
@@ -288,6 +283,7 @@ Create alert tuning rules from the Microsoft Defender XDR **Settings** area or f
288283

289284
> [!NOTE]
290285
> The **alert title (Name)** is based on the **alert type (IoaDefinitionId)**, which decides the alert title. Two alerts that have the same alert type can change to a different alert title.
286+
> The *Hide alert* feature is only available in Defender for Endpoint alerts.
291287
292288
<!--what does this mean?-->
293289

0 commit comments

Comments
 (0)