I want to edit the defender alert to incorporate username of risky user detected.

Pouli Taufui 0 Reputation points
2023-11-07T22:15:00.55+00:00

I know that you can only have the organization name and URL link in defender identity protection alert. I want to know is there a way to add the username of the risky user as well. This would be helpful as there are multiple tenants that require cross referencing and detections do not always happen at real time, there can be clashes with detections occurring at close time proximity.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
{count} votes