Formerly called alert suppression. Defender XDR lets you write rules so that alerts with matching evidence, for example a given file, process or IP address, are hidden or closed automatically, which is handy for known activity like security testing; Microsoft ships some built-in rules too.
Also called formerly alert suppression.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Alert tuning in context, with comparison tables and the common traps.
Terms in this definition
- XDR
Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
Related terms
- Suppression rule
Automatically dismisses Defender for Cloud alerts whose type and entities fit your criteria, scoped either to a subscription (portal or API) or, through Azure Policy, to a management group. Defender portal users would create an alert tuning rule instead.