Forum Discussion
Dean_Gross
Jul 14, 2021Silver Contributor
Unsupported alerts
Can anyone tell me why the Investigation state for some alerts from MCAS show up in M365 Defender as "unsupported alerts" ?
- Feb 06, 2023
Unsupported alert type alert status means, that automated investigation capabilities cannot pick up that alert to run an automated investigation. You can however investigate those alerts manually. See more here: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/review-alerts?view=o365-worldwide
MartinLaabs
Feb 06, 2023Copper Contributor
Unsupported alert type alert status means, that automated investigation capabilities cannot pick up that alert to run an automated investigation. You can however investigate those alerts manually. See more here: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/review-alerts?view=o365-worldwide