Last updated
Was this helpful?
Alerts raised by Microsoft Defender for Office 365 in the selected tenant, narrowed to that product so mail and collaboration threats are not buried among endpoint and identity alerts. Take an alert, move it through its statuses, and open it in the Defender portal when you need the full picture.
The properties returned are for the Graph resource type alert, filtered to serviceSource eq 'microsoftDefenderForOffice365'. For more information on the properties please see the Graph documentation.
The Extended Info flyout goes considerably further than the table, adding the alert description and recommended actions, the evidence and affected resources behind it, the MITRE techniques matched, any named threat or actor, the detection source, and the first and last activity times.
Selecting All Tenants queues a background job that collects alerts from every tenant, and the page tells you it is still loading. Come back in a few minutes for a complete list.
Assign to self
Puts your name on the alert as its owner.
Set status to active
Moves the alert back into the active queue.
Set status to in progress
Marks the alert as being worked on.
Set status to resolved
Closes the alert.
More Info
Opens the Extended Info flyout with the full details for the selected row.
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?
Was this helpful?

