I think that most of what you'd need would be found in "Security & Compliance PowerShell" (https://learn.microsoft.com/en-us/powershell/exchange/scc-powershell?view=exchange-ps). But that's probably something you'll find much in use in plain PowerShell knowledge. The cmdlets for that look to be part of Microsoft Exchange Online.
Microsoft 365 Defender - How to get more meaningful email alerting?
EnterpriseArchitect
5,136
Reputation points
How can I get more meaningful email alerts using the Microsoft 365 Defender?
Because every time I get the email alert, the email is not as informative like the below:
Microsoft 365 Defender has detected a security threat in your environment
View incident details:
ID36931__ID__36931__Incident name__New domains being forwarded emails__Severity__High__Categories__InitialAccess__Time__May 27, 2024, 7:28 UTC__Incident page__https://security.microsoft.com/incidents/How can I get the impacted user email address to query with the PowerShell?
Any help would be greatly appreciated.
Thanks.