Forum Discussion

Dean_Gross's avatar
Dean_Gross
Silver Contributor
Jul 14, 2021
Solved

Unsupported alerts

Can anyone tell me why the Investigation state for some alerts from MCAS show up in M365 Defender as "unsupported alerts" ?

  • Dean_Gross 

     

    Unsupported alert type alert status means, that automated investigation capabilities cannot pick up that alert to run an automated investigation. You can however investigate those alerts manually. See more here: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/review-alerts?view=o365-worldwide

1 Reply

  • MartinLaabs's avatar
    MartinLaabs
    Copper Contributor

    Dean_Gross 

     

    Unsupported alert type alert status means, that automated investigation capabilities cannot pick up that alert to run an automated investigation. You can however investigate those alerts manually. See more here: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/review-alerts?view=o365-worldwide