Managing MDI security alerts
The different alerts in MDI aim to explain suspicious activities detected in the on-premises environment. The alerts can be categorized as follows:
- Reconnaissance phase alerts
- Compromised credentials phase alerts
- Lateral movement phase alerts
- Domain dominance phase alerts
- Exfiltration phase alerts
The alerts that are pre-configured in MDI are categorized using their MITRE ATT&CK ™ tactic as well, and the complete list of alerts can be found at learn.microsoft.com/en-us/defender-for-identity/alerts-overview#security-alert-name-mapping-and-unique-external-ids.
To manage these alerts, we need to head over to the Microsoft 365 Defender portal at security.microsoft.com. We then need to perform the following tasks:
- Go to Incidents & alerts on the left-hand side of the screen and then to Alerts:
Figure 13.5 – The Incidents & alerts menu
- To filter alerts from...