Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsTo investigate a Microsoft 365 security alert, open it in the Microsoft Defender portal, review its evidence and affected entities, then check whether it belongs to a broader incident. Prioritize the incident, establish scope, and choose containment actions based on verified evidence. Check automated investigation results and pending actions before assuming Microsoft has already remediated the threat.
Know what an alert tells you—and what it does not
An alert is an individual signal or piece of evidence. An incident is a correlated collection of alerts and related information that can reveal a wider attack story. Use the alert to understand the specific detection; use its incident to examine related alerts, affected assets, and chronology. Microsoft explains this distinction in its alert investigation guidance.
The Defender portal can bring together alerts from workloads including Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Microsoft Entra ID Protection, Microsoft Sentinel, and Microsoft Purview Data Loss Prevention. Available details and actions vary by alert type and workload, so do not assume every alert offers the same investigation options.
1. Locate the alert and confirm you can access it
In the Microsoft Defender portal, find the alert in the Alerts queue or open it from its incident. The queue can be filtered by severity, status, category, detection source, alert type, product, affected entities, and automated-investigation state. This helps narrow a busy queue without treating the filter itself as a risk assessment.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Access depends on the source and task. Microsoft’s general alert guidance lists roles such as Security Reader, Security Operator, or Security Administrator in Microsoft Entra ID, as well as qualifying custom Defender roles. Sentinel data also requires appropriate permissions on the associated workspace. Check the current role and workload requirements if an alert or its evidence is unavailable.
2. Read the alert and its incident context
Open the alert and review its summary, source, story, chronology, and affected entities. Then check whether it is linked to an incident. Related alerts may represent separate signals from the same broader activity; looking only at one alert can obscure the sequence or scope.
Rank #2
- Note the detection source and what behavior or artifact it identifies.
- Identify affected users, mailboxes, devices, or other entities shown in the alert.
- Review related alerts and activity in the incident before deciding that the alert is isolated.
- Use available entity actions only after confirming what entity they affect; options vary by alert type.
3. Prioritize the incident before taking action
Assess severity, priority, impacted assets, related alerts, and the context available in the incident. Decide whether the case calls for immediate containment, escalation, or continued monitoring. Severity is one input to triage, not a substitute for determining what is affected and whether the activity is ongoing.
Microsoft documents automation rules that can triage, manage, or respond to some incidents when they are created. Their presence does not mean every incident has been handled automatically; confirm the incident’s actual state and actions.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
4. Establish scope from the attack story and evidence
Use the incident’s attack story, alerts, impacted assets, evidence, automated investigations, and related activity to build a defensible picture of scope and impact. The incident graph can help visualize relationships among entities. Depending on the workload, investigate affected users, mailboxes, endpoints, and other evidence surfaced in the portal.
For Defender for Office 365 incidents, Microsoft’s workflow describes an Evidence and Response view that surfaces related items and pending actions. Review the underlying investigation or incident graph when you need more entity detail. Do not treat a proposed remediation as proof that every affected asset has been found.
Rank #4
5. Contain and eradicate based on verified scope
Choose actions that match the evidence and the entities confirmed to be affected. Microsoft gives examples such as disabling compromised users, isolating affected devices, blocking malicious IP addresses, and approving remediation actions. Automated investigation can also identify actions such as quarantining a file, stopping a process, isolating a device, or blocking a URL.
Before approving a proposed action, inspect the affected entity and the action’s scope. Whether remediation runs automatically or waits for approval depends on tenant configuration. Use Action center to review pending actions and track completed ones; Microsoft’s guidance emphasizes that not every alert triggers an automated investigation and not every investigation results in automated remediation. See Automated investigation and response in Microsoft Defender XDR.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
6. Recover, resolve, and improve
After containment, restore affected users, devices, workloads, or tenant resources to a trusted state and validate that the threat is no longer active. Record the outcome, classification, determination, response actions, and resolution details in the incident. Complete outstanding handoffs and tasks before resolving it.
Once the incident is closed, review whether the response exposed a gap in workflows, playbooks, automation rules, detections, or security configuration, and update them where appropriate.
Check licensing and permissions for the specific workload
There is no single Microsoft 365 license requirement that applies to every alert investigation. Microsoft says some alerts can be accessed without a Defender XDR license, giving access through Defender for Office 365 as an example; available settings vary by license level. Check the exact feature and action needed in your tenant rather than inferring requirements from the alert alone.
The specific Office 365 incident workflow in Microsoft’s Defender for Office 365 incident investigation guide requires Defender for Office 365 Plan 2 or higher and sufficient permissions, including Search and purge. That prerequisite is specific to the documented workflow and should not be generalized to all Microsoft 365 alerts. Sentinel alerts have a separate requirement for appropriate Azure RBAC permissions on the associated workspace.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

