How to notify security team members of assigned alerts/incidents in Microsoft Defender

Fraley, David 0 Reputation points
2024-05-29T19:10:08.59+00:00

Is there a way to send email notifications to someone when we assign an alert or incident specifically to them in Microsoft Defender? We already have email notifications set up for new alerts, but we're wondering if there is a way to notify team members when an alert has been assigned to them.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Carlos Solís Salazar 17,626 Reputation points MVP
    2024-05-30T17:59:35.03+00:00

    Hello,

    In Microsoft Defender for Cloud, you can configure email notifications for alerts and attack paths. These notifications ensure timely delivery to the appropriate recipients. Here’s how you can set it up:

    1. Customize Email Notifications in the Portal:
    • Sign in to the Azure portal.
    • Navigate to Microsoft Defender for Cloud > Environment settings.
    • Select the relevant subscription.
    • Choose email notifications.
      • Define the recipients using one or both of these options:
      • From the dropdown list, select from the available roles.
        • Enter specific email addresses separated by commas (there’s no limit to the number of email addresses you can enter).
        • Select the notification types:
          - Notify about alerts with the following severity (or higher) and select a severity level.
          
                - Notify about attack paths with the following risk level (or higher) and select a risk level.
          
      • Click Save.
    1. Customize Email Notifications with an API:

    For Microsoft Defender XDR, you can create rules to determine the devices and alert severities for email notifications. Here’s how:

    1. Sign in to Microsoft Defender XDR using an account with the Security Administrator or Global Administrator role assigned.
    2. In the navigation pane, go to Settings > Endpoints > General > Email notifications

    I hope this helps!

    Remember to accept the answer if it is helpful.

    0 comments No comments

  2. Sandeep G-MSFT 16,201 Reputation points Microsoft Employee
    2024-06-03T06:39:04.6066667+00:00

    @Fraley, David

    Thank you for posting this in Microsoft Q&A.

    You can configure Microsoft Defender XDR to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity.

    If you're using Defender for Business, you can set up email notifications for specific users (not roles or groups).

    You can set the alert severity levels that trigger notifications. You can also add or remove recipients of the email notification. New recipients get notified about alerts triggered after they're added. For more information about alerts, see View and organize the Alerts queue.

    If you're using role-based access control (RBAC), recipients will only receive notifications based on the device groups that were configured in the notification rule. Users with the proper permission can only create, edit, or delete notifications that are limited to their device group management scope. Only users assigned to the Global administrator role can manage notification rules that are configured for all device groups.

    The email notification includes basic information about the alert and a link to the portal where you can do further investigation.

    To create rules for alert notifications you can follow below article,

    https://video2.skills-academy.com/en-us/defender-xdr/configure-email-notifications#create-rules-for-alert-notifications

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments