Advertisement · 728 × 90
#
Hashtag
#DONT_CORR
Advertisement · 728 × 90
Preview
Exclude analytics rules from correlation in Microsoft Defender XDR - Microsoft Defender XDR Learn how to exclude specific analytics rules from the correlation engine to maintain static incident grouping behavior similar to Microsoft Sentinel.

With the unified SOC experience there might be some ANRs you want to exclude from XDR correlation. Now you can!

Either using the UI or add #DONT_CORR# at the beginning of the ANR description.

learn.microsoft.com/en-us/defend...

1 0 0 0