Forum Discussion
Are exclusions in Defender for alerts only?
- Oct 04, 2023
leon_boers if you want to suppress specific alerts in M365 Defender to reduce some false positive alerts, you need to create alert tuning rules (suppression rules) with specific conditions
leon_boers if you want to suppress specific alerts in M365 Defender to reduce some false positive alerts, you need to create alert tuning rules (suppression rules) with specific conditions
- leon_boersOct 06, 2023Copper Contributor
Thanks elieelkarkafi !
I've set up tuning and will monitor how that works.for anyone else wanting to start tuning. if you select "tune alert" from the actual alert, you get pre-populated info (like host names etc) in the tuning drop-downs.
- Oct 06, 2023
leon_boers Correct, that way to fine tune a specific alert with specific hostname , IP , etc....
the other way is to create a tuning with more generic conditions
Please click Mark as Best Response & Like if my post helped you to solve your issue. This will help others to find the correct solution easily.