From 42cc278abcd8967eacc7dfa6e73d394bb72475ad Mon Sep 17 00:00:00 2001 From: Prem Kumar <85905240+PremMS-MDE@users.noreply.github.com> Date: Wed, 15 Jan 2025 17:11:04 +0530 Subject: [PATCH 1/2] Update manage-alerts.md --- defender-endpoint/manage-alerts.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/defender-endpoint/manage-alerts.md b/defender-endpoint/manage-alerts.md index d1c26d77ad..1cb307b838 100644 --- a/defender-endpoint/manage-alerts.md +++ b/defender-endpoint/manage-alerts.md @@ -99,6 +99,8 @@ Create custom rules to control when alerts are suppressed, or resolved. You can 6. Click **Save**. +Note: Alert suppression is not compatible for Custom detection, customer should fine-tune their custom detection to avoid False Positives. + #### View the list of suppression rules 1. In the navigation pane, select **Settings** \> **Endpoints** \> **Rules** \> **Alert suppression**. From bd1a5392d840ca98b6b8900caf4f18ec1dd83026 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 15 Jan 2025 08:56:44 -0800 Subject: [PATCH 2/2] Update manage-alerts.md with new date and note --- defender-endpoint/manage-alerts.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/defender-endpoint/manage-alerts.md b/defender-endpoint/manage-alerts.md index 1cb307b838..5f7d04c310 100644 --- a/defender-endpoint/manage-alerts.md +++ b/defender-endpoint/manage-alerts.md @@ -14,7 +14,7 @@ ms.collection: ms.topic: conceptual ms.subservice: edr search.appverid: met150 -ms.date: 12/18/2020 +ms.date: 01/15/2025 --- # Manage Microsoft Defender for Endpoint alerts @@ -38,6 +38,7 @@ Selecting an alert in either of those places brings up the **Alert management pa :::image type="content" source="media/atp-alerts-selected.png" alt-text="The Alert management pane and the Alerts queue" lightbox="media/atp-alerts-selected.png"::: Watch this video to learn how to use the new Microsoft Defender for Endpoint alert page. + > [!VIDEO https://learn-video.azurefd.net/vod/player?id=8a9c08a6-558c-47a8-a336-d748acbdaa80] ## Link to another incident @@ -99,7 +100,8 @@ Create custom rules to control when alerts are suppressed, or resolved. You can 6. Click **Save**. -Note: Alert suppression is not compatible for Custom detection, customer should fine-tune their custom detection to avoid False Positives. +> [!NOTE] +> Alert suppression is not compatible for custom detections. Make sure to fine-tune your custom detections to avoid [false positives](/defender-endpoint/defender-endpoint-false-positives-negatives). #### View the list of suppression rules