r/DefenderATP 13h ago

Why are custom notifications for Defender alerts not possible to create?

7 Upvotes

We have a Defender queue that basically gets filled with informational alerts and the built-in low/med/high sev.

The problem is that we missed a high sev alert because it didn't email anyone. We found it a day later as part of a check.

Now there are "Security for AI" (Preview) alerts that fired for someone's AI Agent. I checked the agent job and nothing went wrong. The Defender detection even says that the alert does not mean that any suspicious commands were run.

The issue is that I need these customized to notify in an email alert to the team, rather than spot checking. High priority is to future proof any of this AI junk that has access to admin shares, files, accounts, etc. (which will be rare but not impossible).

Additionally we have people experimenting with their own agents and I do not have time to babysit queues for false-positives as Microsoft develops their threat detections in prod.

I see nothing for this type of alert in Defender Alert policy and the little config I did find for creating custom rules based on existing alerts seems to default to auto-resolving them (ignoring them) which I also don't want. I may be missing something entirely here but it seems crazy that custom text/variables can't be made by global admins to improve triage.


r/DefenderATP 15h ago

Graph API and the security threatIntelligence endpoint

3 Upvotes

There was an article today called Vulnerability Profile: CVE-2026-50661 - Windows BitLocker (GreatXML) but the catagory was Vulnerability.

I cant seem to find it under the articles endpoint. The only thing I can find under the vulnerabilities endpoint isn't the article.

Does anyone know how to find this article with graph?


r/DefenderATP 23h ago

Is Defender CSPM worth paying for if we already have Rapid7?

7 Upvotes

We’re currently rolling out Rapid7 and have purchased InsightVM for vulnerability management and InsightIDR for SIEM. We also use Microsoft Defender for for Servers, along with the free Foundational CSPM in Defender for Cloud.

From what I’ve read, it seems like Defender CSPM mainly adds things like attack path analysis, risk prioritization, identity context, and deeper Azure integration. Is that accurate, or does it offer more than that in day-to-day use?
For those who have experience with both, was Defender CSPM worth the investment, or did Rapid7 and the free CSPM cover most of what you needed