Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

An organization is implementing Microsoft Defender for Identity to protect its on-premises Active Directory environment. They have several legacy applications and services that perform legitimate administrative actions using service accounts with elevated privileges, which often trigger benign alerts in Defender for Identity due to their unusual behavior patterns. The security team wants to prevent these specific, known-good activities from generating alerts without compromising the overall detection capabilities for actual threats. Which configuration should they implement in Defender for Identity?

  1. AConfigure an exclusion rule for the specific service accounts/entities.
  2. BSet the alert severity for these activities to 'Informational'.
  3. CDisable the relevant detection sensor on the Domain Controllers.
  4. DCreate a custom detection rule with a suppression query for these activities.
Show answer & explanation

Correct answer: A. Configure an exclusion rule for the specific service accounts/entities.

Configuring an exclusion rule for specific service accounts or entities in Microsoft Defender for Identity allows the security team to prevent known-good, benign activities from generating alerts, while still maintaining the overall detection capabilities for other threats. This is the most precise and recommended way to tune out false positives for legitimate administrative actions.

Why the other options are wrong

  • B. Setting alert severity to 'Informational' would still generate alerts, which the team wants to prevent entirely for these benign actions.
  • C. Disabling the sensor would prevent all detections, including legitimate threats, which is not desired.
  • D. While custom detection rules can have suppression queries, exclusion rules are specifically designed and more straightforward for suppressing known benign activity for specific entities/accounts in Defender for Identity detections.

Defender for Identity Exclusion Rules

Configuration settings in Microsoft Defender for Identity that allow specific entities (users, computers, domains) or activities to be excluded from triggering certain detection alerts.

  • Used to tune out known-good or benign false positives.
  • Helps reduce alert fatigue for security analysts.
  • Can be configured for specific accounts, computers, or detection types.

Memory trick: Exclusion Rules tell Defender for Identity: 'These specific actions are OK, don't worry'.

More Mitigate threats using Microsoft Defender XDR questions