MC1228325 High
(Public Preview) New built in alert tuning rules for Microsoft Defender for Endpoint in Microsoft Defender XDR
Summary AI-generated
Six new built-in alert tuning rules for Defender for Endpoint will auto-handle low-priority alerts; rules visible Feb 8, active by default Feb 18, 2026, with opt-out available.
Suggested actions AI-generated
- Review and optionally disable new MDE alert tuning rules between Feb 8–18, 2026
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1222979 New Built-in Alert Tuning Rules optimize your incident and alert queues
- MC1465771 Microsoft Defender XDR: DLP alerts will be set as behaviors by default
- MC1187386 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
- MC1251207 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1191616 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1234542 Retirement of “Suspected identity theft (pass-the-ticket)” classic alert
Original post from Microsoft
[Introduction]
Microsoft Defender XDR is adding six new Microsoft-curated built-in alert tuning rules for Microsoft Defender for Endpoint (MDE) to help reduce low-priority endpoint alerts reaching your queues.
[When this will happen:]
- February 8, 2026: Rules become visible in the portal (Preview) for review.
- February 8–February 18, 2026: Rules are visible but not active, so you can review and opt out if needed.
- February 18, 2026: Rules become active by default.
[How this affects your organization:]
Who is affected: Admins using Microsoft Defender XDR with MDE.
What will happen:
- With the default experience, you should see fewer informational or low severity endpoint alerts in your incident/alert queues, because matching alerts will be handled automatically.
- Some rules use Resolve and others use Set as Behavior, which reclassifies an alert as a behavior record. These alerts will not appear in open alert queues. They also will not generate incidents, while still remaining available for investigation and hunting.
- You stay in control: all built in rules are visible in Settings > Microsoft Defender XDR > Alert Tuning, and you can disable any rule anytime.
[What you can do to prepare:]
- No action required if you want the default experience.
- To opt out, review and disable any of the new MDE rules during February 8–February 18, 2026 (you can still disable later, but the rules will be on by default starting February 18, 2026).
- If you manage multiple tenants, you can manage rule enablement at scale using Multi-Tenant Organization (MTO) content distribution.
Learn more
- Microsoft Defender XDR Alert Tuning documentation
- Tech Community blog
[Compliance considerations:]
No compliance considerations identified; review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Microsoft Defender XDR will add six new built-in alert tuning rules for Microsoft Defender for Endpoint starting February 8, 2026, to reduce low-priority alerts. Rules are visible for review until February 18, then activate by default but can be disabled anytime by admins. No action needed for default use.