Microsoft has launched a new alert tuning system for Defender XDR that promises long-awaited relief for Security Operations Centers (SOCs) struggling to manage overwhelming alert volumes. The feature, which became generally available today after a public preview, is built to reduce low-value notifications so that analysts can focus on the threats that truly matter.
At launch, the system targets 12 specific rule types within Microsoft Defender for Office 365, suppressing alerts that are considered informational or low severity. By removing routine noise from the analyst workflow, Microsoft aims to help security teams regain control of their investigation queues and focus their energy where it has greater impact.
The company has revealed that early users reported meaningful reductions in alert volumes during testing. With the feature now active for all customers who did not opt out, enterprises are expected to see measurable efficiency gains as their SOCs begin to operate with fewer distractions and more structured alert prioritization.
A Closer Look at How the System Works
Microsoft’s new alert tuning capability is built to balance automation with oversight. Following its review period on January 25, 2026, the system went live for organizations that kept the feature enabled. Those customers are already seeing low-severity alerts automatically triaged, leaving analysts free to examine the issues that genuinely need attention.
The feature works in lockstep with Microsoft’s Automated Investigation and Response (AIR) workflows. When an alert is suppressed, it does not simply vanish. AIR initiates a background investigation that monitors for any indication of elevated risk. If new indicators suggest the alert deserves human review, the system automatically reopens it with a “New” status inside the Defender XDR console. This ensures that automation functions as a smart filter, not a closed gate.
Initially, the 12 alert categories being tuned include user-reported spam, quarantined message requests, and various notifications tied to the Tenant Allow/Block List. Microsoft selected these high-volume categories because they frequently generate low-risk events that still demand analyst confirmation. Automating these saves time without weakening a company’s security posture.
Administrators have full flexibility to customize thresholds and select which alert sets are eligible for suppression. For organizations that manage multiple tenants, Microsoft has extended configuration through its Multi-Tenant Management portal. A single source tenant can push consistent tuning policies across an entire managed estate, creating standardized alert behavior across multiple environments.
Addressing the Growing Alert Fatigue Crisis
Alert fatigue remains one of cybersecurity’s biggest operational challenges. The average enterprise SOC now processes around 10,000 alerts each day, with each one requiring 20 to 40 minutes for proper evaluation. Even fully staffed teams can reliably investigate only a fraction of these alerts, leaving the rest unattended or superficially cleared.




