SHD / MC Checker

MC1481318 | Microsoft Defender XDR: Detection source support in alert tuning rules



MC1481318 | Microsoft Defender XDR: Detection source support in alert tuning rules


Classification stayInformed
Last Updated 09/28/2026 23:56:23
Start Time 09/28/2026 23:55:51
End Time 12/25/2026 08:00:00
Message Content

[What and why]

We are introducing detection source selection for alert tuning rules in Microsoft Defender XDR. This update enables alert tuning rules to be scoped to specific detection sources, providing more granular control over how alert tuning rules are applied.

As part of this update, alert tuning rules will apply to the detection sources selected for each rule. Existing rules that are not updated will apply to all detection sources under their selected service sources, including custom detections.

[Rollout schedule]

  • Public Preview (Worldwide): Rollout begins in mid-October 2026 and is expected to complete in early November 2026.

    • Note: Detection source selection will become available in mid-October 2026, and configured detection source selections will take effect in early November 2026.

  • General Availability (Worldwide): Rollout begins in mid-November 2026 and is expected to complete in early December 2026.

    • Note: Detection source selection will become available in mid-November 2026, and configured detection source selections will take effect in early December 2026.

[Impact on your organization]

Who is affected

  • Organizations that use alert tuning rules in Microsoft Defender XDR.

Platforms and services

  • Microsoft Defender XDR

What will happen

  • Alert tuning rules will be configurable to apply to specific detection sources and apply only to the detection sources selected for each rule.
  • If not updated, existing alert tuning rules will apply to all detection sources under their selected service sources, including custom detections.

Detection source selection

detection sources in alert properties

[Action required and recommendations]

No action is required if existing rules should apply to all detection sources under their selected service sources, including custom detections. Otherwise, we recommend that you review existing alert tuning rules and update the detection source selections as needed.

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Machine Translation

[何となぜ]

Microsoft Defender XDRでアラートチューニングルールの検出ソース選択機能を導入します。このアップデートにより、アラートチューニングルールを特定の検出ソースにスコープ化できるようになり、アラートチューニングルールの適用方法をより細かく制御できるようになりました。

このアップデートの一環として、アラートチューニングルールは各ルールで選択された検出ソースに適用されます。更新されていない既存のルールは、選択したサービスソース下のすべての検出ソース(カスタム検出も含む)に適用されます。

[展開スケジュール]

  • パブリックプレビュー(世界): 展開は2026年10月中旬に始まり、2026年11月初旬に完了する予定です。

    • 注:検出源の選択は2026年10月中旬に利用可能となり、設定済みの検出源選択は2026年11月初旬に適用されます。

  • 一般公開(世界): 展開は2026年11月中旬に始まり、2026年12月初旬に完了する予定です。

    • 注:検出源の選択は2026年11月中旬に利用可能となり、設定された検出源の選択は2026年12月初旬に有効となります。

[組織への影響]

影響を受ける人物

  • Microsoft Defender XDRでアラートチューニングルールを使用している組織。

ホームとサービス

  • Microsoft Defender XDR

何が起こるのか

  • アラートチューニングルールは、特定の検出ソースに適用され、各ルールで選択した検出源にのみ適用されるように設定可能です。
  • 更新されない場合、既存のアラートチューニングルールは、選択したサービスソースの下にあるすべての検出ソースに適用され、カスタム検出も含まれます。

検出源の選択

detection sources in alert properties

[行動が必要と提言]

既存のルールが選択されたサービスソース下のすべての検出ソース(カスタム検出を含む)に適用される場合は、何の対応も不要です。それ以外の場合は、既存のアラートチューニングルールを見直し、必要に応じて検出源の選択を更新することをお勧めします。

[コンプライアンスの考慮事項]

コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。