Monitor and respond
This is the operational queue: alerts that detections raised, incidents they escalate into, and the actions you can take from either.
Nothing arrives here until Detection and Alerting are enabled. See Security Operations.
Alerts
An alert is one detection that fired. It carries a severity on the same five-level scale as everything else in the platform - and, separately, the source's own verbatim severity before normalization.
SCREENSHOT: the alert queue.
That second value is worth knowing about. A vendor's "High" and the platform's High are not necessarily the same judgement, and when you are deciding whether a normalization is treating a source sensibly, the original is what tells you.
Alert statuses
| Status | Meaning |
|---|---|
| New | Raised, untouched |
| Triaging | Being assessed |
| Triaged | Assessed, awaiting action |
| Investigating | Actively worked |
| Resolved | Dealt with |
| Closed | Finished |
| False Positive | Not a real detection |
| Suppressed | Muted by a suppression rule |
Suppressed is distinct from False Positive on purpose. Suppressed means a rule you wrote muted it; False Positive means an analyst judged this instance wrong. Reading a suppressed alert as an analyst verdict would overstate how much anyone actually looked at.
AI triage
If enabled, alerts are scored before a human sees them. Each triaged alert carries:
- A priority score from 0 to 100
- Reasoning - why it scored that way
- A recommendation - suggested next steps
- The model that produced it
The score is a queue-ordering aid, not a verdict. The reasoning is the useful part: it tells you what the triage actually keyed on, which is what lets you decide whether to trust it on this class of alert.
It spends tokens, so it fails closed - if the service gating it is unavailable, triage stops rather than proceeding. An outage cannot start spending on your behalf.
Incidents
An incident groups related alerts into one piece of work. Escalate when several alerts are one event, or when something needs a response rather than a verdict.
| Status | Meaning |
|---|---|
| New | Raised |
| Investigating | Being worked |
| Contained | Spread stopped, not yet fixed |
| Remediated | Fixed |
| Closed | Finished |
| False Positive | Not a real incident |
Contained before Remediated is the distinction that matters under pressure. Stopping an attacker moving is a different milestone from removing them, and collapsing the two loses the ability to say "we have stopped the bleeding, we are not yet clean" - which is exactly what people ask during an incident.
Incidents also carry a sub-status recording what is happening inside the current phase:
| Phase | Sub-statuses |
|---|---|
| Investigation | Gathering Evidence, Analyzing, Correlating |
| Containment | Isolated, Blocked, Account Disabled, System Quarantined |
| Remediation | Remediating |
| Handling | Escalated, On Hold |
These are what make a status meaningful to someone joining mid-incident. "Investigating" tells them little; "Investigating / Correlating" tells them where to pick up.
Response actions
Available from an alert or an incident, depending on what the affected system is connected through - isolating a host, blocking an indicator, disabling an account, quarantining a system. The containment sub-statuses above record which were taken.
Guardrails on automated response are evaluated before an action runs. If a guardrail cannot be evaluated, the action is allowed with its safety check skipped rather than blocked.
That is a deliberate availability choice - a guardrail service outage does not stop incident response - but it means an alert is raised for exactly that case, and it is the only signal that an action ran unchecked. Treat one seriously: it means something happened without the constraint you configured.
Where alerts come from
Alerts are not only produced by the platform's own detections. They also arrive from connected sources, each keeping its identity so you can tell what saw what:
- Microsoft 365 - security alerts, management activity, Intune
- Entra ID and Azure - sign-ins, risk detections, audit, provisioning, activity logs
- Network and security appliances - Barracuda, Fortinet, Palo Alto, Cisco
- Endpoint - CrowdStrike
- Your own collectors and agents
- Custom - anything you raise yourself through the API
API
The endpoints behind this section are in the API reference.
Next
- Investigations - searching the events behind an alert
- Detection engineering - tuning what raises alerts
- Endpoint security - device-level response