M365DEF-002: Alert policy inventory
- Platform
- Entra ID / M365
- Category
- Defender for Office 365
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Alert policies in Microsoft 365 Defender generate notifications when specific security events or suspicious activities are detected, enabling timely incident response. Without a comprehensive set of alert policies, critical security events such as mass file deletions, impossible travel, or malware campaigns may go unnoticed for extended periods. Reviewing the alert policy inventory ensures that all important threat categories have corresponding detection and notification mechanisms.
Recommended value
All default alert policies enabled; custom alert policies for organization-specific threats; alert recipients configured for the security team
Remediation
Review all default and custom alert policies in the Microsoft 365 Defender portal and ensure that default security alert policies have not been disabled or modified to reduce their effectiveness. Configure alert notification recipients to include the security operations team and verify that email notifications are being delivered and monitored. Create custom alert policies for organization-specific threat scenarios such as unusual mail flow patterns, bulk permission changes, or access from blocked geographies.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.DEFENDER.5.1v1, MS.DEFENDER.5.2v1
- NIST SP 800-53
- SI-4, AU-5