| MC1481318 | Microsoft Defender XDR: Detection source support in alert tuning rules |
|---|
| Classification | stayInformed |
|---|---|
| Last Updated | 09/28/2026 23:56:23 |
| Start Time | 09/28/2026 23:55:51 |
| End Time | 12/25/2026 08:00:00 |
| Message Content |
[What and why]
We are introducing detection source selection for alert tuning rules in Microsoft Defender XDR. This update enables alert tuning rules to be scoped to specific detection sources, providing more granular control over how alert tuning rules are applied.
As part of this update, alert tuning rules will apply to the detection sources selected for each rule. Existing rules that are not updated will apply to all detection sources under their selected service sources, including custom detections.
[Rollout schedule]
[Impact on your organization]
Who is affected
Platforms and services
What will happen
Detection source selection
[Action required and recommendations]
No action is required if existing rules should apply to all detection sources under their selected service sources, including custom detections. Otherwise, we recommend that you review existing alert tuning rules and update the detection source selections as needed.
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
|
| Machine Translation |
[何となぜ]
Microsoft Defender XDRでアラートチューニングルールの検出ソース選択機能を導入します。このアップデートにより、アラートチューニングルールを特定の検出ソースにスコープ化できるようになり、アラートチューニングルールの適用方法をより細かく制御できるようになりました。
このアップデートの一環として、アラートチューニングルールは各ルールで選択された検出ソースに適用されます。更新されていない既存のルールは、選択したサービスソース下のすべての検出ソース(カスタム検出も含む)に適用されます。
[展開スケジュール]
[組織への影響]
影響を受ける人物
ホームとサービス
何が起こるのか
検出源の選択
[行動が必要と提言]
既存のルールが選択されたサービスソース下のすべての検出ソース(カスタム検出を含む)に適用される場合は、何の対応も不要です。それ以外の場合は、既存のアラートチューニングルールを見直し、必要に応じて検出源の選択を更新することをお勧めします。
[コンプライアンスの考慮事項]
コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。
|
