For the complete documentation index, see llms.txt. This page is also available as Markdown.

MDO Alerts

Alerts raised by Microsoft Defender for Office 365 in the selected tenant, narrowed to that product so mail and collaboration threats are not buried among endpoint and identity alerts. Take an alert, move it through its statuses, and open it in the Defender portal when you need the full picture.

Table Details

The properties returned are for the Graph resource type alert, filtered to serviceSource eq 'microsoftDefenderForOffice365'. For more information on the properties please see the Graph documentation.

The Extended Info flyout goes considerably further than the table, adding the alert description and recommended actions, the evidence and affected resources behind it, the MITRE techniques matched, any named threat or actor, the detection source, and the first and last activity times.

Selecting All Tenants queues a background job that collects alerts from every tenant, and the page tells you it is still loading. Come back in a few minutes for a complete list.

Table Actions

Action
Description
Bulk Action Available

Assign to self

Puts your name on the alert as its owner.

Set status to active

Moves the alert back into the active queue.

Set status to in progress

Marks the alert as being worked on.

Set status to resolved

Closes the alert.

More Info

Opens the Extended Info flyout with the full details for the selected row.


Feature Requests/Ideas

We value your feedback and ideas. Please raise any feature requests on GitHub.

Last updated

Was this helpful?