> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/alerts/monitored-alerts/m365-defender-incidents-and-alerts.md).

# M365 Defender (Incidents & Alerts)

Sourced from Microsoft 365 Defender, Microsoft Cloud App Security, and Microsoft Sentinel. This is the largest catalog — requires **Entra ID P2** licensing, since Augmentt pulls from Defender's own incidents and alerts API.

{% hint style="warning" %}
To expose this data for Augmentt to pull, a client needs to go to **Security > Incidents & Alerts > Alerts** in the Microsoft 365 Defender portal.
{% endhint %}

{% hint style="info" %}
References: [Incidents and alerts in the Microsoft Defender portal](https://learn.microsoft.com/en-us/defender-xdr/incidents-overview) for Defender-native detections, and [Anomaly detection policies in Microsoft Defender for Cloud Apps](https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy) for the Cloud App Security-sourced rows (category "Microsoft Cloud App Security" below).
{% endhint %}

| Alert                                                                                                                                           | Category                              | Severity      | What it alerts on                                                                             |
| ----------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------- | --------------------------------------------------------------------------------------------- |
| **Activities from suspicious user agents** `office365_activities_from_suspicious_user_agents`                                                   | Microsoft Cloud App Security          | Low           | Sign-in or activity was detected from a user agent string associated with known attack tools. |
| **Suspicious browser** `office365_suspicious_browser`                                                                                           | Microsoft Cloud App Security          | Variable      | Activity was detected from a browser exhibiting suspicious characteristics.                   |
| **Activity from a Tor IP address** `office365_activity_from_a_tor_ip_address`                                                                   | Microsoft Cloud App Security          | Variable      | User activity originated from a known Tor exit node IP.                                       |
| **Activity from infrequent country** `office365_activity_from_infrequent_country`                                                               | Microsoft Cloud App Security          | Variable      | Activity was detected from a country the user hasn't signed in from before.                   |
| **Admin Submission Result Completed** `office365_admin_submission_result_completed`                                                             | Threat Management                     | Informational | An admin's submission of a message, URL, or file for analysis has completed.                  |
| **Admin triggered manual investigation of email** `office365_admin_triggered_manual_investigation_of_email`                                     | Threat Management                     | Informational | An admin manually started an investigation into a specific email.                             |
| **Admin triggered user compromise investigation** `office365_admin_triggered_user_compromise_investigation`                                     | Threat Management                     | Medium        | An admin started an automated investigation into a potentially compromised user.              |
| **Admin confirmed user compromised** `office365_admin_compromised`                                                                              | Threat Management                     | Informational | An admin confirmed that a flagged user account is compromised.                                |
| **Anomalous Token** `office365_anomalous_token`                                                                                                 | Anomalous Token                       | Variable      | A sign-in token was used in an unusual or unexpected way.                                     |
| **Token issuer anomaly** `office365_token_issuer`                                                                                               | Anomalous Token                       | Variable      | A token was issued by an unexpected or anomalous issuer.                                      |
| **Anonymous IP address** `office365_anonymous_ip_address`                                                                                       | Anonymous Login                       | Variable      | Activity was detected from an anonymizing proxy or VPN IP address.                            |
| **Block SharePoint File Download** `office365_block_sharepoint_file_download`                                                                   | Microsoft Cloud App Security          | Medium        | A SharePoint file download was blocked by policy.                                             |
| **Creation of forwarding/redirect rule** `office365_creation_of_forwardingredirect_rule`                                                        | Threat Management                     | Informational | A new mail forwarding or redirect rule was created.                                           |
| **DLP-High volume of content detected U.S. Financial Data** `office365_dlphigh_volume_of_content_detected_us_financial_data`                    | Data Loss Prevention                  | High          | A high volume of U.S. financial data matched a DLP policy.                                    |
| **DLP-Low volume of content detected U.S. PII** `office365_dlplow_volume_of_content_detected_us_pii`                                            | Data Loss Prevention                  | Low           | A small volume of U.S. personal data matched a DLP policy.                                    |
| **DLP-U.K. PII: Scan content shared outside - low count** `office365_dlpuk_pii_scan_content_shared_outside__low_count`                          | Data Loss Prevention                  | Medium        | A small amount of U.K. personal data was shared outside the organization.                     |
| **eDiscovery search started or exported** `office365_ediscovery_search_started_or_exported`                                                     | Threat Management                     | Informational | An eDiscovery search was started, or its results were exported.                               |
| **Email messages containing malicious file removed after delivery** `office365_email_messages_containing_malicious_file_removed_after_delivery` | Threat Management                     | Informational | A malicious file attachment was removed from mailboxes after it had already been delivered.   |
| **Email messages containing malicious URL removed after delivery** `office365_email_messages_containing_malicious_url_removed_after_delivery`   | Threat Management                     | Informational | A malicious link was removed from email messages after delivery.                              |
| **Email messages from a campaign removed after delivery** `office365_email_messages_from_a_campaign_removed_after_delivery`                     | Threat Management                     | Informational | Messages from an identified phishing or malware campaign were removed after delivery.         |
| **Email reported by user as malware or phish** `office365_email_reported_by_user_as_malware_or_phish`                                           | Threat Management                     | Low           | A user reported a message as malware or phishing.                                             |
| **Email sending limit exceeded** `office365_email_sending_limit_exceeded`                                                                       | Threat Management                     | Medium        | A mailbox exceeded its outbound email sending limit.                                          |
| **Honeytoken activity** `office365_honeytoken_activity`                                                                                         | Honeytoken Activity Security Alert    | Medium        | Activity was detected on a deliberately planted decoy (honeytoken) account.                   |
| **Mail Forward Rule Enabled** `office365_mail_forward_rule_enabled`                                                                             | Mail Flow                             | Medium        | A mailbox rule that auto-forwards mail externally was enabled.                                |
| **Mailbox Permissions Change** `office365_mailbox_permissions_change`                                                                           | Access Governance                     | High          | Permissions on a mailbox were changed.                                                        |
| **Malware detection** `office365_malware_detection`                                                                                             | Microsoft Cloud App Security          | Medium        | Malware was detected in a file or attachment.                                                 |
| **Mass download** `office365_mass_download`                                                                                                     | Threat Detection                      | Variable      | An unusually large volume of files was downloaded.                                            |
| **Mass download by a single user** `office365_mass_download_by_a_single_user`                                                                   | Threat Detection                      | Variable      | One user downloaded an unusually large volume of files.                                       |
| **Multiple failed user logon attempts to a service** `office365_multiple_failed_user_logon_attempts_to_a_service`                               | Microsoft Cloud App Security          | Variable      | A user had repeated failed logon attempts to a cloud service.                                 |
| **New APP detected in Organization** `office365_new_app_detected_in_organization`                                                               | Microsoft Cloud App Security          | Low           | A new third-party app was detected connecting to the tenant.                                  |
| **New app with score 0-4** `office365_new_app_with_score_04_`                                                                                   | Microsoft Cloud App Security          | Low           | A newly detected app has a low Microsoft security score (0–4).                                |
| **New popular app** `office365_new_popular_app`                                                                                                 | Microsoft Cloud App Security          | Variable      | A widely-used third-party app was newly detected in the tenant.                               |
| **OAuthCreation** `office365_oauthcreation`                                                                                                     | Microsoft Cloud App Security          | Low           | A new OAuth app registration was created.                                                     |
| **Password spray** `office365_password_spray`                                                                                                   | Password Spray                        | High          | A password-spray attack (many accounts, few passwords each) was detected.                     |
| **Distributed Password cracking attempts in AzureAD** `office365_distributed_password_cracking_attempts_in_azuread`                             | Azure Sentinel                        | Medium        | Coordinated password-cracking attempts were detected against Entra ID.                        |
| **Explicit MFA Deny** `office365_explicit_mfa_deny`                                                                                             | Azure Sentinel                        | Medium        | A user explicitly denied an MFA prompt they didn't initiate.                                  |
| **Brute force attack against Azure Portal** `office365_brute_force_attack_against_azure_portal`                                                 | Azure Sentinel                        | Medium        | Repeated sign-in attempts against the Azure portal were detected.                             |
| **Multiple Password Reset by user** `office365_multiple_password_reset_by_user`                                                                 | Azure Sentinel                        | Variable      | A user reset their password multiple times in a short window.                                 |
| **Permission changes** `office365_permission_changes`                                                                                           | Microsoft Cloud App Security          | Low           | Permissions were changed on an app, mailbox, or resource.                                     |
| **Phish delivered due to an ETR override** `office365_phish_delivered_due_to_an_etr_override`                                                   | Threat Management                     | Informational | A phishing message was delivered because a mail flow rule overrode filtering.                 |
| **Phish delivered due to an IP allow policy** `office365_phish_delivered_due_to_an_ip_allow_policy`                                             | Threat Management                     | Informational | A phishing message was delivered because a trusted IP allow policy bypassed filtering.        |
| **Remote code execution attempt** `office365_remote_code_execution_attempt`                                                                     | Remote Execution Security Alert       | Medium        | An attempt to execute code remotely on a system was detected.                                 |
| **Suspicious inbox manipulation rule** `office365_suspicious_inbox_manipulation_rule`                                                           | Microsoft Cloud App Security          | High          | A mailbox rule was created that suspiciously manipulates or hides incoming mail.              |
| **Traffic detected from IP addresses recommended for blocking** `office365_traffic_detected_from_ip_addresses_recommended_for_blocking`         | Network Traffic from Unrecommended IP | Low           | Traffic was seen from an IP address on Microsoft's block-recommendation list.                 |
| **Unfamiliar sign-in properties** `office365_unfamiliar_signin_properties`                                                                      | Unfamiliar Location                   | Variable      | A sign-in had properties (location, device, etc.) unfamiliar for that user.                   |
| **Unusual volume of file deletion** `office365_unusual_volume_of_file_deletion`                                                                 | Data Governance                       | Medium        | An unusually high number of files were deleted in a short time.                               |
| **Users targeted by phish campaigns** `office365_users_targeted_by_phish_campaigns`                                                             | Threat Management                     | High          | One or more users were targeted by an identified phishing campaign.                           |
| **Leaked credentials** `office365_leaked_creds`                                                                                                 | Leaked Credentials                    | Variable      | A user's credentials were found in a known leaked-credential dataset.                         |
| **Azure AD threat intelligence** `office365_azure_threat_intel`                                                                                 | Threat Intelligence                   | Variable      | Microsoft's threat intelligence flagged activity associated with known attack patterns.       |
| **Malicious IP address** `office365_malicious_ip`                                                                                               | Anonymous Login                       | Variable      | Activity was detected from an IP address known to be malicious.                               |
| **Additional risk detected** `office365_additional_risk_detect`                                                                                 | Threat Management                     | Variable      | Microsoft detected additional risk signals on top of an existing alert.                       |
| **Fail User Login Attempt** `office365_failed_user_login_attempt`                                                                               | Access Governance                     | Medium        | A user's login attempt failed.                                                                |
| **Ergo-Flex Mail Flow** `office365_ergoflex_mail_flow`                                                                                          | Mail Flow                             | High          | A mail flow anomaly matching the Ergo-Flex detection pattern was found.                       |
| **Unsanctioned Cloud App Access was Blocked** `office365_unsanctioned_cloud_app_access_was_blocked`                                             | Suspicious Activity                   | Informational | Access to an unsanctioned, unapproved cloud app was blocked.                                  |
| **Phishing Attempts** `office365_phishing_attempts`                                                                                             | Threat Management                     | Medium        | A phishing attempt was detected targeting the organization.                                   |
| **SharePoint File Operation from New IP** `office365_sharepointfileoperation_via_previously_unseen_ips`                                         | Data Loss Prevention                  | Medium        | A SharePoint file operation occurred from an IP not seen before for that user.                |
| **Logon from an Outdated Browser** `office365_logon_from_an_outdated_browser`                                                                   | Microsoft Cloud App Security          | Low           | A user signed in using an outdated, less-secure browser.                                      |
| **DLP-ID Number Policy** `office365_dlpid_number_policy`                                                                                        | Data Loss Prevention                  | High          | Content matching a government or personal ID number pattern triggered a DLP policy.           |
| **Stale Externally Shared Files** `office365_stale_externally_shared_files`                                                                     | Microsoft Cloud App Security          | Low           | Files shared externally haven't been accessed in a long time.                                 |
| **External Shared File** `office365_external_shared_file`                                                                                       | Threat Management                     | Variable      | A file was shared with someone outside the organization.                                      |
| **Uploaded Sensitive File to 3rd Party App or Service** `office365_uploaded_sensitive_file_to_3rd_party_app_or_service`                         | Threat Management                     | Medium        | A sensitive file was uploaded to a third-party app or service.                                |
| **365 Mailbox Permissions** `office365_365_mailbox_permissions`                                                                                 | Threat Management                     | High          | Mailbox permissions were changed in Microsoft 365.                                            |
| **User requested to release a quarantined message** `office365_user_requested_to_release_a_quarantined_message`                                 | Threat Management                     | Informational | A user asked for a quarantined message to be released to their inbox.                         |
| **Granted Access to Another Mailbox** `office365_granted_access_to_another_mailbox`                                                             | Access Governance                     | Medium        | A user was granted access to another user's mailbox.                                          |
| **Externally Shared Folder or Document** `office365_shared_folder_document_outside`                                                             | Data Loss Prevention                  | Medium        | A folder or document was shared with an external party.                                       |
| **Externally Shared File** `office365_shared_file_externally`                                                                                   | Data Governance                       | Medium        | A file was shared externally, flagged from a data-governance perspective.                     |
| **Granted Mailbox Permission** `office365_granted_mailbox_permission`                                                                           | Access Governance                     | Medium        | Mailbox permission was granted to a user.                                                     |
| **New Application Added** `office365_new_application_added`                                                                                     | Microsoft Cloud App Security          | Low           | A new application was registered or added in the tenant.                                      |
| **Suspicious Email Sending Patterns Detected** `office365_suspicious_email_sending_patterns_detected`                                           | Threat Management                     | Medium        | A mailbox showed sending patterns consistent with compromise or abuse.                        |
| **Activity from a Password Spray Associated IP Address** `office365_activity_from_a_passwordspray_associated_ip_address`                        | Microsoft Cloud App Security          | Medium        | Activity was seen from an IP address linked to a known password-spray attack.                 |
| **Privileged Accounts Sign In Failure Spikes** `office365_privileged_accounts__sign_in_failure_spikes`                                          | Threat Management                     | High          | A privileged account had a sudden spike in failed sign-in attempts.                           |
| **Rare application consent** `office365_rare_application_consent`                                                                               | Threat Management                     | Medium        | A user granted consent to an app that's rarely consented to.                                  |
| **Rare and potentially high-risk Office operations** `office365_rare_and_potentially_highrisk_office_operations`                                | Threat Management                     | Low           | A user performed an uncommon, potentially risky Office 365 operation.                         |
| **Attempt to bypass conditional access rule in Microsoft Entra ID** `office365_attempt_to_bypass_conditional_access_rule_in_azure_ad`           | Threat Management                     | Low           | An attempt was detected to work around a Conditional Access policy.                           |
| **A potentially malicious URL click was detected** `office365_a_potentially_malicious_url_click_was_detected`                                   | Threat Management                     | High          | A user clicked a link flagged as potentially malicious.                                       |
| **Allow/block list entry is about to expire** `office365_tenant_allowblock_list_entry_is_about_to_expire`                                       | Exchange                              | Informational | A tenant allow/block list entry is nearing its expiration date.                               |
| **Unusual addition of credentials to an OAuth app** `office365_unusual_addition_of_credentials_to_an_oauth_app`                                 | Microsoft Cloud App Security          | Medium        | New credentials (a secret or certificate) were added to an OAuth app unexpectedly.            |
| **Elevation of exchange admin privilege** `office365_elevation_of_exchange_admin_privilege`                                                     | Access Governance                     | Low           | A user's Exchange admin privileges were elevated.                                             |
| **Suspicious sequence of exploration activities** `office365_suspicious_sequence_of_exploration_activities`                                     | Access Governance                     | Low           | A user performed a suspicious sequence of resource-exploration actions.                       |
| **User restricted from sending email** `office365_user_restricted_from_sending_email`                                                           | Threat Management                     | High          | A mailbox was restricted from sending email, usually due to suspected compromise.             |
| **Multiple failed login attempts** `office365_multiple_failed_login_attempts`                                                                   | Threat Management                     | Low           | A user had multiple consecutive failed login attempts.                                        |
| **A user clicked through to a potentially malicious URL** `office365_a_user_clicked_through_to_a_potentially_malicious_url`                     | Threat Management                     | High          | A user followed a link flagged as potentially malicious.                                      |
| **Suspicious authentication activity** `office365_suspicious_authentication_activity`                                                           | Access Governance                     | Medium        | Authentication activity for a user matched a suspicious pattern.                              |
| **Consent to application** `consent_to_application`                                                                                             | Microsoft Cloud App Security          | Informational | A user or admin granted an app consent to access tenant data.                                 |
| **Reset user password** `reset_user_password`                                                                                                   | Access Governance                     | Informational | A user's password was reset.                                                                  |
| **Reset password (by admin)** `reset_password_by_admin`                                                                                         | Access Governance                     | Informational | An admin reset a user's password.                                                             |
| **Add conditional access policy** `add_conditional_access_policy`                                                                               | Access Governance                     | Informational | A new Conditional Access policy was created.                                                  |
| **Delete conditional access policy** `delete_conditional_access_policy`                                                                         | Access Governance                     | Informational | A Conditional Access policy was deleted.                                                      |

{% hint style="info" %}
The last several rows (Consent to Application, Reset User Password, Reset Password by Admin, Add/Delete Conditional Access Policy) also appear under **M365 Monitored Alerts** — they're the same underlying event surfaced through both collection paths, not a separate alert.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/alerts/monitored-alerts/m365-defender-incidents-and-alerts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
