Microsoft Defender: Changes to Defender for Cloud Apps alerts
Coming soon for Microsoft Defender for Cloud Apps: A change to alerts generated by events originating from Defender for Cloud Apps that are generated in the Microsoft Defender XDR detection engine A change to App governance alerts This rollout aims to provide more accurate and precise information on the origin of these alerts, enabling customers to identify, manage, and respond to alerts more effectively. When this will happen: General Availability (GCC, GCC High, DoD, Production, DoD): We will begin rolling out early March 2025 and expect to complete by early April 2025. How this will affect your organization: We will change the field indicating the alert source in the alert data itself. Note: The rollout will only affect new alerts generated after the rollout and will not alter existing alerts. This rollout will be reflected in all experiences where alerts are represented, including Incidents & alerts queues in the XDR portal, Advanced hunting, and the correlating APIs and SIEM systems. In the Defender XDR portal, the change will be reflected in the Service sources field, replacing the current Microsoft Defender XDR and App governance values with the new value Defender for Cloud Apps. The detection sources will remain unchanged and will continue to indicate the detections are generated in the XDR detection engine, App governance policy, or App governance detection. The alert ID prepended characters of some of the alerts will also be changed to comply with the Defender XDR mapping. Service/Detection sources filter in the Incidents queue. Left: Before the change. Right: After the change: View image in new tab Learn more about the different alert sources in Defender XDR in the Alert sources section of Investigate alerts in Microsoft Defender XDR – Microsoft Defender XDR | Microsoft Learn In the Microsoft Graph API, Microsoft Defender for Endpoint streaming API, and the Microsoft Azure Events Hub, the change will be reflected in the alert resource type under the property serviceSource, and the previous values of microsoft365Defender and microsoftAppGovernance will change to microsoftDefenderForCloudApps. Learn more about the Graph API alert resource: alert resource type – Microsoft Graph v1.0 | Microsoft […]
The post Microsoft Defender: Changes to Defender for Cloud Apps alerts appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender: Changes to Defender for Cloud Apps alerts
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Teams: Intelligent call recap in Queues app
Microsoft Teams Queues app will introduce Intelligent call recap for recorded call queue calls, providing AI-generated summaries, key points, ...
Microsoft Teams Rooms on Android: room users can change the app language
Teams Rooms on Android will allow users to temporarily change the app language per session from the console, aligning with Windows experience....
Microsoft Teams: Facilitator can join channel meetings
Microsoft Teams will allow adding Facilitator to channel meetings to take notes, manage agendas, answer questions, and handle tasks. Rollout s...
Microsoft Teams: Copilot in call recap in the Queues app
Microsoft Teams is adding Copilot in call recap within the Queues app for recorded call queue calls, enabling users with Microsoft 365 Copilot...
Prepare for upcoming changes to the Excel Exchange connector
New Exchange Mail and Calendar connectors for Excel Power Query will replace the current Microsoft Exchange connector by April 2027. Workbook ...
Microsoft Teams: Proximity join support for attendees in Teams events from Teams Rooms on Windows and Android
Microsoft Teams Rooms on Windows and Android will support proximity join for attendees in Teams events, enabling quick connection to nearby ro...
Microsoft Teams: Add multiple steps when building a workflow from scratch
Microsoft Teams Workflows will soon support multiple sequential actions in a single workflow, enabling richer automations to reduce manual tas...
Microsoft Purview | Information Protection – Auto-labeling scale increase for SharePoint and OneDrive
Microsoft Purview auto-labeling for SharePoint and OneDrive increases daily processing from 100,000 to 500,000 files per tenant, enabling fast...
Create interactive slides in PowerPoint with Copilot skill (Windows)
PowerPoint for Windows now includes a Copilot skill to create interactive, full-slide visuals for explaining complex concepts, timelines, comp...
Outlook: Purview DLP Wait-on-Send Support for Mac
Outlook for Mac will support Microsoft Purview Data Loss Prevention (DLP) wait-on-send policies. Organizations can require a DLP evaluation be...