Microsoft 365 Defender - How to get more meaningful email alerting?

EnterpriseArchitect 5,136 Reputation points
2024-05-27T13:00:44.4566667+00:00

How can I get more meaningful email alerts using the Microsoft 365 Defender?

Because every time I get the email alert, the email is not as informative like the below:

Microsoft 365 Defender has detected a security threat in your environment

View incident details:

ID36931__ID__36931__Incident name__New domains being forwarded emails__Severity__High__Categories__InitialAccess__Time__May 27, 2024, 7:28 UTC__Incident page__https://security.microsoft.com/incidents/How can I get the impacted user email address to query with the PowerShell?

Any help would be greatly appreciated.

Thanks.

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,445 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,328 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rich Matheisen 45,906 Reputation points
    2024-05-28T15:31:10.0266667+00:00

    I think that most of what you'd need would be found in "Security & Compliance PowerShell" (https://learn.microsoft.com/en-us/powershell/exchange/scc-powershell?view=exchange-ps). But that's probably something you'll find much in use in plain PowerShell knowledge. The cmdlets for that look to be part of Microsoft Exchange Online.

    0 comments No comments