Microsoft 365 Defender - How to get more meaningful email alerting?

EnterpriseArchitect 4,956 Reputation points

How can I get more meaningful email alerts using the Microsoft 365 Defender?

Because every time I get the email alert, the email is not as informative like the below:

Microsoft 365 Defender has detected a security threat in your environment

View incident details:

ID36931__ID__36931__Incident name__New domains being forwarded emails__Severity__High__Categories__InitialAccess__Time__May 27, 2024, 7:28 UTC__Incident page__ can I get the impacted user email address to query with the PowerShell?

Any help would be greatly appreciated.


Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,121 questions
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,235 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rich Matheisen 45,416 Reputation points

    I think that most of what you'd need would be found in "Security & Compliance PowerShell" ( But that's probably something you'll find much in use in plain PowerShell knowledge. The cmdlets for that look to be part of Microsoft Exchange Online.

    0 comments No comments