Forum Discussion
packetknight
Dec 23, 2024Copper Contributor
"Duplicate" alerts in Defender for Cloud from MDE
Hello,
I discovered that security alerts generated from Defender for Endpoint are causing "duplicate" security alerts in Defender for Cloud.
We have several Azure Arc-enabled servers active with Defender for Server P1 which includes Defender for Endpoint integration. Hence Arc servers are automatically onboarded to Defender for Endpoint.
We had a false positive caused by the addition of AV exclusions which generated an alert / incident in Defender XDR which was then synced to Sentinel. Closing the alerts in Defender XDR or Sentinel resulted in synced status between the two. However it seems the same alerts were also created in Defender for Cloud, and their status remained "open" even after being resolved in Defender XDR.
The link in the open Defender for Cloud Alert effectively opens up the resolved alert in Defender XDR. So it seems to be the same alert but its status is not being synced.
Is this a known issue?
- ohekpejeCopper Contributor
Hello, I would suggest you engage MS via a support request to look into your issue.