From the course: Microsoft 365 Administrator Expert (MS-102) Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 25,200 courses taught by industry experts.

Review and respond to security incidents and alerts in Microsoft 365 Defender

Review and respond to security incidents and alerts in Microsoft 365 Defender - Microsoft 365 Tutorial

From the course: Microsoft 365 Administrator Expert (MS-102) Cert Prep by Microsoft Press

Review and respond to security incidents and alerts in Microsoft 365 Defender

- In this lesson, we will review and respond to security incidents and alerts in Microsoft 365 Defender. This is really important area where security professionals can directly review on Microsoft Defender Portal, and then see the alerts that are generated by Microsoft 365 Defender, and see what are the remediations to these kind of alerts. Let's explore alert policies in Microsoft 365. Basically, alerts are the basis of all incidents and it will indicate the occurrence of malicious or suspicious events in your organization depending on what are the threat avenues of your organization. For example, previously, we discussed there are four areas where you can see and concentrate on these alerts. These alerts are generated based on identity, apps, and data, and also the devices if you onboarded devices to Microsoft 365 Defender. And alerts are typically part of broader attack and provide some clues about the…

Contents