{"id":18762,"date":"2026-09-29T09:02:17","date_gmt":"2026-09-29T00:02:17","guid":{"rendered":"https:\/\/m365jp.net\/?p=18762"},"modified":"2026-09-29T09:05:38","modified_gmt":"2026-09-29T00:05:38","slug":"mc1481318-microsoft-defender-xdr-detection-source-support-in-alert-tuning-rules","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2026-09-29-mc1481318-microsoft-defender-xdr-detection-source-support-in-alert-tuning-rules","title":{"rendered":"MC1481318 | Microsoft Defender XDR: Detection source support in alert tuning rules"},"content":{"rendered":"<div class=\"postie-post\">\n<div>&#013; <\/p>\n<hr>\n<p>&#013; <\/p>\n<table id=\"section\">&#013; <\/p>\n<tbody>&#013; <\/p>\n<tr>&#013; <\/p>\n<th width=\"95%\">MC1481318 | Microsoft Defender XDR: Detection source support in alert tuning rules<\/th>\n<p>&#013; <\/tr>\n<p>&#013; <\/tbody>\n<p>&#013; <\/table>\n<p>&#013; <\/p>\n<hr>\n<p>&#013; <\/p>\n<table id=\"data\">&#013; <\/p>\n<tbody>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>Classification<\/th>\n<p>&#013; <\/p>\n<td>stayInformed<\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>Last Updated<\/th>\n<p>&#013; <\/p>\n<td>09\/28\/2026 23:56:23<\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>Start Time<\/th>\n<p>&#013; <\/p>\n<td>09\/28\/2026 23:55:51<\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>End Time<\/th>\n<p>&#013; <\/p>\n<td>12\/25\/2026 08:00:00<\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>Message Content<\/th>\n<p>&#013; <\/p>\n<td>&#013; <\/p>\n<p><b>[What and why]<\/b><\/p>\n<p>&#013; <\/p>\n<p>We are introducing detection source selection for alert tuning rules in Microsoft Defender XDR. This update enables alert tuning rules to be scoped to specific detection sources, providing more granular control over how alert tuning rules are applied.<\/p>\n<p>&#013; <\/p>\n<p>As part of this update, alert tuning rules will apply to the detection sources selected for each rule. Existing rules that are not updated will apply to all detection sources under their selected service sources, including custom detections.<\/p>\n<p>&#013; <\/p>\n<p><b>[Rollout schedule]<\/b><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li> <b>Public Preview (Worldwide):<\/b> Rollout begins in mid-October 2026 and is expected to complete in early November 2026.&#013;\n<ul>&#013; <\/p>\n<li>Note: Detection source selection will become available in mid-October 2026, and configured detection source selections will take effect in early November 2026.<\/li>\n<\/ul>\n<p>&#013; <\/li>\n<li> <b>General Availability (Worldwide):<\/b> Rollout begins in mid-November 2026 and is expected to complete in early December 2026.&#013;\n<ul>&#013; <\/p>\n<li>Note: Detection source selection will become available in mid-November 2026, and configured detection source selections will take effect in early December 2026.<\/li>\n<\/ul>\n<p>&#013; <\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><b>[Impact on your organization]<\/b><\/p>\n<p>&#013; <\/p>\n<p><i>Who is affected<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>Organizations that use alert tuning rules in Microsoft Defender XDR.<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>Platforms and services<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>Microsoft Defender XDR<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>What will happen<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>Alert tuning rules will be configurable to apply to specific detection sources and apply only to the detection sources selected for each rule.<\/li>\n<li>If not updated, existing alert tuning rules will apply to all detection sources under their selected service sources, including custom detections.<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>Detection source selection<\/i><\/p>\n<p>&#013; <\/p>\n<p><img decoding=\"async\" alt=\"detection sources in alert properties\" src=\"https:\/\/support.microsoft.com\/en-us\/customercomms\/media\/messagecenter\/2026\/09\/21718-1.png\"><\/p>\n<p>&#013; <\/p>\n<p><b>[Action required and recommendations]<\/b><\/p>\n<p>&#013; <\/p>\n<p>No action is required if existing rules should apply to all detection sources under their selected service sources, including custom detections. Otherwise, we recommend that you review existing alert tuning rules and update the detection source selections&#013;  as needed.<\/p>\n<p>&#013; <\/p>\n<p><b>[Compliance considerations]<\/b><\/p>\n<p>&#013; <\/p>\n<p>No compliance considerations identified. Review as appropriate for your organization.<\/p>\n<p>&#013; <\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/p>\n<tr>&#013; <\/p>\n<th>Machine Translation<\/th>\n<p>&#013; <\/p>\n<td>&#013; <\/p>\n<p><b>[\u4f55\u3068\u306a\u305c]<\/b><\/p>\n<p>&#013; <\/p>\n<p>Microsoft Defender XDR\u3067\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u306e\u691c\u51fa\u30bd\u30fc\u30b9\u9078\u629e\u6a5f\u80fd\u3092\u5c0e\u5165\u3057\u307e\u3059\u3002\u3053\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306b\u3088\u308a\u3001\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u3092\u7279\u5b9a\u306e\u691c\u51fa\u30bd\u30fc\u30b9\u306b\u30b9\u30b3\u30fc\u30d7\u5316\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u3001\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u306e\u9069\u7528\u65b9\u6cd5\u3092\u3088\u308a\u7d30\u304b\u304f\u5236\u5fa1\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>&#013; <\/p>\n<p>\u3053\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306e\u4e00\u74b0\u3068\u3057\u3066\u3001\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u306f\u5404\u30eb\u30fc\u30eb\u3067\u9078\u629e\u3055\u308c\u305f\u691c\u51fa\u30bd\u30fc\u30b9\u306b\u9069\u7528\u3055\u308c\u307e\u3059\u3002\u66f4\u65b0\u3055\u308c\u3066\u3044\u306a\u3044\u65e2\u5b58\u306e\u30eb\u30fc\u30eb\u306f\u3001\u9078\u629e\u3057\u305f\u30b5\u30fc\u30d3\u30b9\u30bd\u30fc\u30b9\u4e0b\u306e\u3059\u3079\u3066\u306e\u691c\u51fa\u30bd\u30fc\u30b9(\u30ab\u30b9\u30bf\u30e0\u691c\u51fa\u3082\u542b\u3080)\u306b\u9069\u7528\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>&#013; <\/p>\n<p><b>[\u5c55\u958b\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb]<\/b><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li> <b>\u30d1\u30d6\u30ea\u30c3\u30af\u30d7\u30ec\u30d3\u30e5\u30fc(\u4e16\u754c):<\/b> \u5c55\u958b\u306f2026\u5e7410\u6708\u4e2d\u65ec\u306b\u59cb\u307e\u308a\u30012026\u5e7411\u6708\u521d\u65ec\u306b\u5b8c\u4e86\u3059\u308b\u4e88\u5b9a\u3067\u3059\u3002&#013;\n<ul>&#013; <\/p>\n<li>\u6ce8:\u691c\u51fa\u6e90\u306e\u9078\u629e\u306f2026\u5e7410\u6708\u4e2d\u65ec\u306b\u5229\u7528\u53ef\u80fd\u3068\u306a\u308a\u3001\u8a2d\u5b9a\u6e08\u307f\u306e\u691c\u51fa\u6e90\u9078\u629e\u306f2026\u5e7411\u6708\u521d\u65ec\u306b\u9069\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>&#013; <\/li>\n<li> <b>\u4e00\u822c\u516c\u958b(\u4e16\u754c):<\/b> \u5c55\u958b\u306f2026\u5e7411\u6708\u4e2d\u65ec\u306b\u59cb\u307e\u308a\u30012026\u5e7412\u6708\u521d\u65ec\u306b\u5b8c\u4e86\u3059\u308b\u4e88\u5b9a\u3067\u3059\u3002&#013;\n<ul>&#013; <\/p>\n<li>\u6ce8:\u691c\u51fa\u6e90\u306e\u9078\u629e\u306f2026\u5e7411\u6708\u4e2d\u65ec\u306b\u5229\u7528\u53ef\u80fd\u3068\u306a\u308a\u3001\u8a2d\u5b9a\u3055\u308c\u305f\u691c\u51fa\u6e90\u306e\u9078\u629e\u306f2026\u5e7412\u6708\u521d\u65ec\u306b\u6709\u52b9\u3068\u306a\u308a\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>&#013; <\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><b>[\u7d44\u7e54\u3078\u306e\u5f71\u97ff]<\/b><\/p>\n<p>&#013; <\/p>\n<p><i>\u5f71\u97ff\u3092\u53d7\u3051\u308b\u4eba\u7269<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>Microsoft Defender XDR\u3067\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u7d44\u7e54\u3002<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>\u30db\u30fc\u30e0\u3068\u30b5\u30fc\u30d3\u30b9<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>Microsoft Defender XDR<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>\u4f55\u304c\u8d77\u3053\u308b\u306e\u304b<\/i><\/p>\n<p>&#013; <\/p>\n<ul>&#013; <\/p>\n<li>\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u306f\u3001\u7279\u5b9a\u306e\u691c\u51fa\u30bd\u30fc\u30b9\u306b\u9069\u7528\u3055\u308c\u3001\u5404\u30eb\u30fc\u30eb\u3067\u9078\u629e\u3057\u305f\u691c\u51fa\u6e90\u306b\u306e\u307f\u9069\u7528\u3055\u308c\u308b\u3088\u3046\u306b\u8a2d\u5b9a\u53ef\u80fd\u3067\u3059\u3002<\/li>\n<li>\u66f4\u65b0\u3055\u308c\u306a\u3044\u5834\u5408\u3001\u65e2\u5b58\u306e\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u306f\u3001\u9078\u629e\u3057\u305f\u30b5\u30fc\u30d3\u30b9\u30bd\u30fc\u30b9\u306e\u4e0b\u306b\u3042\u308b\u3059\u3079\u3066\u306e\u691c\u51fa\u30bd\u30fc\u30b9\u306b\u9069\u7528\u3055\u308c\u3001\u30ab\u30b9\u30bf\u30e0\u691c\u51fa\u3082\u542b\u307e\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>&#013; <\/p>\n<p><i>\u691c\u51fa\u6e90\u306e\u9078\u629e<\/i><\/p>\n<p>&#013; <\/p>\n<p><img decoding=\"async\" alt=\"detection sources in alert properties\" src=\"https:\/\/support.microsoft.com\/en-us\/customercomms\/media\/messagecenter\/2026\/09\/21718-1.png\"><\/p>\n<p>&#013; <\/p>\n<p><b>[\u884c\u52d5\u304c\u5fc5\u8981\u3068\u63d0\u8a00]<\/b><\/p>\n<p>&#013; <\/p>\n<p>\u65e2\u5b58\u306e\u30eb\u30fc\u30eb\u304c\u9078\u629e\u3055\u308c\u305f\u30b5\u30fc\u30d3\u30b9\u30bd\u30fc\u30b9\u4e0b\u306e\u3059\u3079\u3066\u306e\u691c\u51fa\u30bd\u30fc\u30b9(\u30ab\u30b9\u30bf\u30e0\u691c\u51fa\u3092\u542b\u3080)\u306b\u9069\u7528\u3055\u308c\u308b\u5834\u5408\u306f\u3001\u4f55\u306e\u5bfe\u5fdc\u3082\u4e0d\u8981\u3067\u3059\u3002\u305d\u308c\u4ee5\u5916\u306e\u5834\u5408\u306f\u3001\u65e2\u5b58\u306e\u30a2\u30e9\u30fc\u30c8\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u30eb\u30fc\u30eb\u3092\u898b\u76f4\u3057\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u691c\u51fa\u6e90\u306e\u9078\u629e\u3092\u66f4\u65b0\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<p>&#013; <\/p>\n<p><b>[\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u306e\u8003\u616e\u4e8b\u9805]<\/b><\/p>\n<p>&#013; <\/p>\n<p>\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u306e\u8003\u616e\u4e8b\u9805\u306f\u7279\u5b9a\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u3002\u7d44\u7e54\u306b\u5fdc\u3058\u305f\u9069\u5207\u306a\u30ec\u30d3\u30e5\u30fc\u3092\u884c\u3063\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>&#013; <\/td>\n<p>&#013; <\/tr>\n<p>&#013; <\/tbody>\n<p>&#013; <\/table>\n<p>&#013;<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&#013; &#013; &#013; &#013; &#013; MC1481318 | Microsoft Defender XDR: Detection source support in alert tunin [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-18762","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/18762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=18762"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/18762\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=18762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=18762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=18762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}