Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics.
Study notes & practiceBrief · concepts · checklist · exercise
Study brief
Microsoft Defender XDR can send separate email notifications for new incidents, completed or failed response actions, and new or updated threat analytics reports. Each notification type has its own rule, scope, recipients, and test workflow under Settings > Microsoft Defender XDR > Email notifications.
Key concepts
- Incident rules can filter by alert severity, detection source, and device group. Defender sends one email for each new incident that matches the rule rather than one email for every alert in the incident.
- Response-action rules can filter manual or automated actions by action type, device group, and completion status. Custom detections that contain response actions are not supported by these notifications.
- Threat analytics rules can notify recipients about all new or updated reports or only reports that match selected threat types and tags.
- Recipients receive tenant-specific links, so access still depends on portal permissions and role scope. Creating notification rules requires permission to manage security settings.
Exam checklist
- Choose the correct notification category for an incident, response action, or threat intelligence report.
- Configure a rule name, scope or filters, recipient addresses, and notification frequency where available.
- Recognize the effect of severity, detection-source, device-group, action-status, threat-type, and tag filters.
- Send a test notification and verify both delivery and the recipient's authorization to open the linked portal record.
Hands-on exercise
Build and validate three Defender XDR notification rules
- Open Settings > Microsoft Defender XDR > Email notifications and review the Incidents, Actions, and Threat analytics tabs.
- Create a narrowly scoped incident rule for high-severity incidents from selected detection sources and add a test recipient.
- Draft equivalent rules for failed response actions and selected threat analytics report types or tags.
- Use the test function, confirm delivery, and document which events do and do not trigger each rule.