Email notifications in Defender XDR
ObjectiveConfigure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
Defender XDR sends email from notification rules on one settings page, with separate tabs for incidents, response actions, and threat analytics reports.
Read the full explanationHide the full explanation
All three notification types live in Settings > Microsoft Defender XDR > Email notifications, under General. Each tab has its own rules, and each rule has a name, its settings, and a list of recipients. You can send a test email before saving, and deleting a rule is permanent. Configuring notifications takes the Manage security settings permission, or Security Administrator or higher when you use basic permissions.
Incident notification rules fire for new incidents or updates to existing ones. You filter by alert severity, and the page describes choosing severities per service source or detection source (for example, only Medium and High for EDR). You can scope a rule to all device groups or selected ones, send only one email per incident, and add the organization name and a tenant-specific portal link. The email carries the incident name, severity, and categories and links straight to the incident.
Response action rules, on the Actions tab, cover manual actions, automated actions (automatic attack disruption and automated investigation and response), or both. You pick the specific actions, the device group scope, and whether to be told when an action completes, fails, or both. They don't cover custom detections that include response actions.
Threat analytics rules notify you when reports are published or updated. A rule can cover every report or only reports of a certain type or with a specific tag. Names and descriptions accept only English letters and numbers.
Remember for the exam
- Incident, action, or report? Pick the matching tab on the same Email notifications page.
- With RBAC, you can only manage and receive notifications for device groups you can manage.
- New recipients get only notifications for events after they are added.
On Microsoft Learn
- Get incident notifications by email in Microsoft Defender XDR ↗
- Get email notifications for response actions in Microsoft Defender XDR ↗
- Get email notifications for Threat analytics updates in Microsoft Defender XDR ↗
- Configure alert notifications (Configure for alerts and detections in Microsoft Defender for Endpoint) ↗