Article
Alert policies in the Microsoft Defender portal
learn.microsoft.com
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Informational Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. Email messages from a campaign removed after delivery Generates an alert when any messages associated with a Campaign are delivered to mailboxes in your organization. If this event occurs, Microsoft removes the infected messages from Exchange Online mailboxes using Zero-hour auto purge. This policy automatically triggers automated investigation and response in Office 365. For more information on this new policy, see Alert policies. Informational Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. Email messages removed after delivery Generates an alert when any malicious messages that don't contain a malicious entity (URL or File), or associated with a Campaign, are delivered to mailboxes in your organization. If this event occurs, Microsoft removes the infected messages from Exchange Online mailboxes using Zero-hour auto purge. This policy automatically triggers automated investigation and response in Office 365. For more information on this new policy, see Alert policies. Informational Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. Email reported by user as junk Generates an alert when users in your organization report messages as junk using the built-in Report button in Outlook or the Report Message add-in. For more information about the add-ins, see Use the Report Message add-in. Low No E1/F1/G1, E3/F3/G3, or E5/G5 Email reported by user as malware or phish Generates an alert when users in your organization report messages as phishing using the built-in Report button in Outlook or the Report Message or Report Phishing add-ins. For more information about the add-ins, see Use the Report Message add-in. “Generates an alert when someone in your organization has sent more mail than is allowed by the outbound spam policy.” Messages containing malicious entity not removed after delivery Generates an alert when any message containing malicious content (file, URL, campaign, no entity), is delivered to mailboxes in your organization. If this event occurs, Microsoft attempted to remove the infected messages from Exchange Online mailboxes using Zero-hour auto purge, but the message wasn't removed due to a failure. Additional investigation is recommended. This policy automatically triggers automated investigation and response in Office 365. Medium Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. MIP AutoLabel simulation completed Generates an alert when anservice-side auto-labeling policy in simulation mode has completed. Low No E5/G5. Phish delivered due to an ETR override1 Generates an alert when Microsoft detects an Exchange transport rule (also known as a mail flow rule) that allowed delivery of a high confidence phishing message to a mailbox. For more information about Exchange Transport Rules (Mail flow rules), see Mail flow rules (transport rules) in Exchange Online. Informational No E1/F1/G1, E3/F3/G3, or E5/G5 Phish delivered due to an IP allow policy1 Generates an alert when Microsoft detects an IP allow policy that allowed delivery of a high confidence phishing message to a mailbox. For more information about the IP allow policy (connection filtering), see Configure the default connection filter policy - Office 365. Informational No E1/F1/G1, E3/F3/G3, or E5/G5 Phish not zapped because ZAP is disabled1 Generates an alert when Microsoft detects delivery of a high confidence phishing message to a mailbox because Zero-Hour Auto Purge for Phish messages is disabled. Informational No E5/G5 or Defender for Office 365 Plan 2 add-on subscription. Potential nation-state activity Microsoft Threat Intelligence Center detected an attempt to compromise accounts from your tenant.
The admin receives an email notification and an alert. This alert provides guidance on how to investigate, revert changes, and unblock a restricted connector. To learn how to respond to this alert, see Respond to a compromised connector. High No E1/F1/G1, E3/F3/G3, or E5/G5 Suspicious email forwarding activity Generates an alert when someone in your organization has autoforwarded email to a suspicious external account. This is an early warning for behavior that might indicate the account is compromised, but not severe enough to restrict the user. Although it's rare, an alert generated by this policy might be an anomaly. It's a good idea to check whether the user account is compromised. High No E1/F1/G1, E3/F3/G3, or E5/G5 Suspicious email sending patterns detected Generates an alert when someone in your organization has sent suspicious email and is at risk of being restricted from sending email. This is an early warning for behavior that might indicate that the account is compromised, but not severe enough to restrict the user. Although it's rare, an alert generated by this policy might be an anomaly. However, it's a good idea to check whether the user account is compromised. Medium Yes E1/F1/G1, E3/F3/G3, or E5/G5 Suspicious tenant sending patterns observed Generates an alert when Suspicious sending patterns have been observed in your organization, which might lead to your organization being blocked from sending emails. Investigate any potentially compromised user and admin accounts, new connectors, or open relays to avoid tenant exceed threshold blocks. For more information about why organizations are blocked, see Fix email delivery issues for error code 5.7.7xx in Exchange Online. High No E1/F1/G1, E3/F3/G3, or E5/G5 Teams message reported by user as security risk This alert is triggered when users report a Teams message as a security risk. Low No E5/G5 or Defender for Office 365 add-on. “Generates an alert when too much email is being sent from unregistered domains (also known as unprovisioned domains).” To request the release of quarantined messages, the Allow recipients to request a message to be released from quarantine (PermissionToRequestRelease) permission is required in the quarantine policy (for example, from the Limited access preset permissions group). For more information, see Allow recipients to request a message to be released from quarantine permission. Informational No Microsoft Business Basic, Microsoft Business Standard, Microsoft Business Premium, E1/F1/G1, E3/F3/G3, or E5/G5 User restricted from sending email Generates an alert when someone in your organization is restricted from sending outbound mail. This alert typically indicates a compromised account where the user is listed on the Restricted entities page at https://security.microsoft.com/restrictedentities. For more information about restricted users, see Remove blocked users from the Restricted entities page. High Yes Microsoft Business Basic, Microsoft Business Standard, Microsoft Business Premium, E1/F1/G1, E3/F3/G3, or E5/G5 User restricted from sharing forms and collecting responses Generates an alert when someone in your organization is restricted from sharing forms and collecting responses using Microsoft Forms due to detected repeated phishing attempt behavior. High No E1, E3/F3, or E5
Go to the Default alert policies section in this article for a list and description of the available alert policies. “Alert policies let you categorize the alerts that are triggered by a policy, apply the policy to all users in your organization, set a threshold level for when an alert is triggered, and decide whether to receive email notifications when alerts are triggered.” Note
Go to the Default alert policies section in this article for a list and description of the available alert policies. “There's also a Alerts page where you can view and filter alerts, set an alert status to help you manage alerts, and then dismiss alerts after you address or resolve the underlying incident.” Note
Informational No E1/F1/G1, E3/F3/G3, or E5/G5 Email messages containing malicious file removed after delivery Generates an alert when any messages containing a malicious file are delivered to mailboxes in your organization. If this event occurs, Microsoft removes the infected messages from Exchange Online mailboxes using Zero-hour auto purge. This policy automatically triggers automated investigation and response in Office 365. For more information on this new policy, see Alert policies. Informational Yes E1/F1/G1, E3/F3/G3, or E5/G5 Email messages containing malicious URL removed after delivery Generates an alert when any messages containing a malicious URL are delivered to mailboxes in your organization. If this event occurs, Microsoft removes the infected messages from Exchange Online mailboxes using Zero-hour auto purge. This policy automatically triggers automated investigation and response in Office 365. For more information on this new policy, see Alert policies. Informational Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. Email messages containing malware removed after delivery Note: This alert policy was replaced by Email messages containing malicious file removed after delivery. This alert policy will eventually go away, so we recommend disabling it and using Email messages containing malicious file removed after delivery instead. For more information, see Alert policies. Informational Yes E5/G5 or Defender for Office 365 Plan 2 add-on subscription. Email messages containing phish URLs removed after delivery Note: This alert policy was replaced by Email messages containing malicious URL removed after delivery. This alert policy will eventually go away, so we recommend disabling it and using Email messages containing malicious URL removed after delivery instead. For more information, see Alert policies. “Generates an alert when users in your organization report messages as junk using the built-in Report button in Outlook or the Report Message add-in.” For Defender for Office 365 Plan 2, E5, G5 customers, this alert automatically triggers automated investigation and response in Defender for Office 365 Plan 2. Low Yes E3/G3, Microsoft 365 Business Premium, Defender for Office 365 Plan 1 add-on, E5/G5, or Defender for Office 365 Plan 2 add-on. Email reported by user as not junk Generates an alert when users in your organization report messages as not junk the built-in Report button in Outlook or the Report Message add-in. For more information about the add-ins, see Use the Report Message add-in. Low No E1/F1/G1, E3/F3/G3, or E5/G5 Email sending limit exceeded Generates an alert when someone in your organization has sent more mail than is allowed by the outbound spam policy. This is usually an indication the user is sending too much email or that the account might be compromised. If you get an alert generated by this alert policy, it's a good idea to check whether the user account is compromised. Medium No E1/F1/G1, E3/F3/G3, or E5/G5 Failed exact data match upload Generates an alert when a user receives the following error when uploading an exact data match based sensitive information type: New sensitive information failed to upload. Try again later. High No E5/G5. Form blocked due to potential phishing attempt Generates an alert when the system detects suspected phishing behavior in a form. High No E1, E3/F3, or E5 Form flagged and confirmed as phishing Generates an alert when a form created in Microsoft Forms from within your organization is identified as potential phishing through Report Abuse and confirmed as phishing by Microsoft. High No E1, E3/F3, or E5 Malware not zapped because ZAP is disabled Generates an alert when Microsoft detects delivery of a malware message to a mailbox because Zero-Hour Auto Purge for Phish messages is disabled. Informational No E5/G5 or Defender for Office 365 Plan 2 add-on subscription.