Managing MDI exclusions
There are three types of exclusion in MDI we can leverage to reduce false positives. All are managed from the Excluded entities section of Microsoft 365 Defender portal | Settings | Identities.
First up, let’s consider Global excluded entities. These are IPs, domains, devices, or users. These pretty much do what they say on the tin. If you want to stop these entities from appearing in any alerts, list them here. It should go without saying that you should proceed with caution: are you completely certain these entities couldn’t produce true positives?
Then, we have a more fine-grained approach: Exclusions by detection rule. This would ideally be used instead of the global option because we’re limiting our potential blind spots. Navigating to this setting, you’ll find the full list of MDI detection types and then the ability to add entities to exclude (only supported entities, varying by detection type). For example, the Suspicious...