Microsoft Secure Tech Accelerator
Apr 13 2023, 07:00 AM - 12:00 PM (PDT)
Microsoft Tech Community

Responding to alerts limitations

Occasional Contributor

This is more a suggestion to Microsoft unless I am missing a trick :)

 

When responding to alerts in Cloud App Security, you don't have the option to mark that you are investigating the alert, only options to dismiss, resolve or adjust policy.

This causes multiple Analysts to investigate the same alert. We need some way of showing that someone is actively investigating the alert, and avoid people thinking the alert is new.. (Similar to options available in Windows Defender ATP alert responses.)

1 Reply

@Christo De Lange 

 

Thank you for your feedback - this is something we're investigating.