Is there any way that we can check the alerts set up to send to our helpdesk, so it can start our ticketing process?
The best I have found so far is manually opening these for every separate customer to try and setup the settings
So starting from https://securitycenter.microsoft.com for each customer, going to Settings, and following the mentioned path, or navigating to the URL on the right in turn with each customer tenantID filled in
Incident Notifs | M365 Defender > Email Notifs > Incidents | https://security.microsoft.com/securitysettings/defender/email_notifications?emailNotificationRuleType=incidents&tid=<EachCustomerTenantID> |
Actions | M365 Defender > Email Notifs > Actions | https://security.microsoft.com/securitysettings/defender/email_notifications?emailNotificationRuleType=actions&tid=<EachCustomerTenantID> |
Threat Analytics | M365 Defender > Email Notifs > Threat Analytics | https://security.microsoft.com/securitysettings/defender/email_notifications?emailNotificationRuleType=threat_analytics&tid=<EachCustomerTenantID> |
Alert Tuning/Suppression | M365 Defender > Alert Tuning | https://security.microsoft.com/securitysettings/defender/alert_suppression?tid=<EachCustomerTenantID> |
Endpoint Alerts | Endpoints > Email Notifications > Alerts | https://security.microsoft.com/securitysettings/endpoints/email_notifications?childviewid=alerts&tid=<EachCustomerTenantID> |
Endpoint Vulnerabilities | Endpoints > Email Notifications > Vulnerabilities | https://security.microsoft.com/securitysettings/endpoints/email_notifications?childviewid=vulnerabilities&tid=<EachCustomerTenantID> |
Identity Health Notifs | Microsoft Defender for Identity > Health Issues | https://security.microsoft.com/settings/identities?tabid=healthIssuesNotifications&tid=<EachCustomerTenantID> |
Identity Alerts | Microsoft Defender for Identity > Alert | https://security.microsoft.com/settings/identities?tabid=securityAlertsNotifications&tid=<EachCustomerTenantID> |
I can't find any place in any of the APIs for Defender that I can query or set them up with