Microsoft 365 Defender - How to get more meaningful email alerting?

EnterpriseArchitect 6,061 Reputation points
2024-05-27T13:00:44.4566667+00:00

How can I get more meaningful email alerts using the Microsoft 365 Defender?

Because every time I get the email alert, the email is not as informative like the below:

Microsoft 365 Defender has detected a security threat in your environment

View incident details:

ID36931__ID__36931__Incident name__New domains being forwarded emails__Severity__High__Categories__InitialAccess__Time__May 27, 2024, 7:28 UTC__Incident page__https://security.microsoft.com/incidents/How can I get the impacted user email address to query with the PowerShell?

Any help would be greatly appreciated.

Thanks.

Windows for business | Windows Server | User experience | PowerShell
Microsoft Security | Microsoft Graph
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rich Matheisen 47,906 Reputation points
    2024-05-28T15:31:10.0266667+00:00

    I think that most of what you'd need would be found in "Security & Compliance PowerShell" (https://learn.microsoft.com/en-us/powershell/exchange/scc-powershell?view=exchange-ps). But that's probably something you'll find much in use in plain PowerShell knowledge. The cmdlets for that look to be part of Microsoft Exchange Online.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.