Home › Glossary › Alert tuning

Alert tuning

Formerly called alert suppression. Defender XDR lets you write rules so that alerts with matching evidence, for example a given file, process or IP address, are hidden or closed automatically, which is handy for known activity like security testing; Microsoft ships some built-in rules too.

Also called formerly alert suppression.

Read more: Microsoft Learn

In the Ultra Transcenders books

SC-200SC-401

Each book explains Alert tuning in context, with comparison tables and the common traps.

Terms in this definition

Related terms

See Alert tuning in the full glossary