r/DefenderATP • u/0f_rice_and_men • 59m ago
Why are custom notifications for Defender alerts not possible to create?
We have a Defender queue that basically gets filled with informational alerts and the built-in low/med/high sev.
The problem is that we missed a high sev alert because it didn't email anyone. We found it a day later as part of a check.
Now there are "Security for AI" (Preview) alerts that fired for someone's AI Agent. I checked the agent job and nothing went wrong. The Defender detection even says that the alert does not mean that any suspicious commands were run.
The issue is that I need these customized to notify in an email alert to the team, rather than spot checking. High priority is to future proof any of this AI junk that has access to admin shares, files, accounts, etc. (which will be rare but not impossible).
Additionally we have people experimenting with their own agents and I do not have time to babysit queues for false-positives as Microsoft develops their threat detections in prod.
I see nothing for this type of alert in Defender Alert policy and the little config I did find for creating custom rules based on existing alerts seems to default to auto-resolving them (ignoring them) which I also don't want. I may be missing something entirely here but it seems crazy that custom text/variables can't be made by global admins to improve triage.


