Defender alerts and TenantAdmins group

adv_kd 135 Reputation points
2024-08-08T06:23:37.13+00:00

Hello,
I have a question about alerts in Defender. There is a default rule "User requested to release a quarantined message". By default as recipient there is a group "TenantAdmins"
User's image

I am using PIM and I am eligible to be an admin, I don't have this role perma-active. And today I did a test - I did not activate my role and I requested to release email from quarantine - and I did not receive email about it unlike my colleague who had role assigned as active.

Is it expected behaviour? I'd like to have alert which sent emails to admins who are eligible in PIM to be an admin. Can I achieve it w/o creating a new group and adding it to all Alert policies?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Raja Pothuraju 23,715 Reputation points Microsoft External Staff Moderator
    2024-08-09T13:45:44.0533333+00:00

    Hello @adv_kd,

    Thank you for posting your query on Microsoft Q&A.

    Based on the information provided, the behavior you experienced is expected. When using Privileged Identity Management (PIM) and your admin role is not active, you won't receive alerts when a quarantined message is released. This is because alerts configured to be sent to the "TenantAdmins" group only include active members of that role.

    Currently, there is no way to send emails to admins who have not activated their roles at the time a quarantined message is released. To address this, you can create a new group, add the required users as members, and update the alert policies to include this new group as recipients of the alerts. This way, the members of the group will receive email notifications when a quarantined message is released.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know. Thanks,
    Raja Pothuraju.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.