Forum Discussion

manthan999's avatar
manthan999
Copper Contributor
Aug 01, 2022

Category assignment to generated alerts

Microsoft defender for cloud apps allows to create policies which when observed in connected apps, generate alerts. These generated alerts have field named "category". I want to understand how names are assigned to this category field of the generated alerts. Is there predefined list of categories for default policies? For example there is default policy called "Suspicious inbox manipulation rule". If this policy triggers an alert then what will be the category for the policy in alert logs?

Resources