Forum Discussion
Aar123
Microsoft
Feb 09, 2026Observed Automation Discrepancies
Hi Team ... I want to know the logic behind the Defender XDR Automation Engine . How it works ?
I have observed Defender XDR Automation Engine Behavior contrary to expectations of identical inc...
raqim88
Feb 16, 2026Copper Contributor
I’ve noticed similar behavior. According to me, Defender XDR’s automation engine can apply built-in automated actions for certain high-severity alerts, even if your custom rules don’t trigger them. It seems designed to reduce alert fatigue, but it can be confusing since these actions aren’t always fully visible in the activity log. Worth reaching out to Microsoft support or checking the detailed automation docs to understand exactly which alert types and conditions trigger these automated closures.