Reviewing and Responding to Security Incidents and Alerts in Microsoft 365 Defender
Alerts represent individual risk items or threats, such as an email that triggers a data loss prevention (DLP) policy action or a macro that queries a computer’s filesystem. When threats are detected in the organization through any of the Microsoft 365 Defender signals, they will show up on the Alerts page of Microsoft 365 Defender.
When working with incidents and alerts in the Microsoft 365 platform, Microsoft recommends a three-phased approach – Triage, Investigate, and Respond – as shown in Figure 7.10:
Figure 7.10 – The Microsoft 365 Incident Management phases
The first phase, Triage, involves determining whether the alerts generated are indeed real (true positives) or not (false positives). In the Investigate phase, potentially affected assets are isolated or disabled (or, if automation is already in place that has disabled and isolated...