Security alerts email notifications

metalheart 411 Reputation points
2024-08-23T05:05:09.8566667+00:00

I have enabled Microsoft Defender for Cloud antimalware protection on a single storage account. Upon uploading an EICAR file I see security alerts with severity High are created, but I'm not getting any email notifications about them despite doing the setup in the environment settings for the subscription (Microsoft Defender for Cloud -> Environment Settings -> click on the 3 dots next to the subscription where the account resides -> Edit Settings).

I am the subscription owner, but also tried entering my email into the additional email address field without success.

What am I missing?

User's image

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
3,202 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Nehruji R 8,181 Reputation points Microsoft External Staff Moderator
    2024-08-27T06:34:52.53+00:00

    Hello metalheart,

    Greetings! Welcome to Microsoft Q&A Platform.

    I understand that you are facing issue in receiving the alert emails from Defender for cloud. The Email Recipients defined with "Roles" would be the only ones who would receive the email. So, in your case, please check user account that have specific privileges only then they would receive notification emails.

    User's image

    If you don't have roles enabled, then you may have email addresses added in Additional email addresses (separated by commas), with dedicated users whom you want to receive email for alters regardless of their PIM status.

    You can configure Microsoft Defender XDR to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity.

    If you're using Defender for Business, you can set up email notifications for specific users (not roles or groups).

    You can set the alert severity levels that trigger notifications. You can also add or remove recipients of the email notification. New recipients get notified about alerts triggered after they're added. For more information about alerts, see View and organize the Alerts queue.

    If you're using role-based access control (RBAC), recipients will only receive notifications based on the device groups that were configured in the notification rule. Users with the proper permission can only create, edit, or delete notifications that are limited to their device group management scope. Only users assigned to the Global administrator role can manage notification rules that are configured for all device groups.

    The email notification includes basic information about the alert and a link to the portal where you can do further investigation.

    To confirm the process of creation on rules for alert notifications you can follow below article,

    https://learn.microsoft.com/en-us/defender-xdr/configure-email-notifications#create-rules-for-alert-notifications

    I have often seen the alerts get blocked before for people who had spam filters on their emails, so they should make sure to check their spam and junk sections. If possible, the receivers should also make sure that they allow the sender of azure-noreply@microsoft.com. If the users have any email security products, or if you have any conflicting email application rules, the alerts may also get blocked.

    Additional Link: Tutorial: Create a policy using the Defender for Cloud Apps policy templates Support and troubleshooting Microsoft Defender for Cloud Apps,https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications,

    https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts

    Hope this answer helps! Please let us know if you have any further queries. I’m happy to assist you further.


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.