Skip to content

Defender for Endpoint alerts: triage basics

Read Microsoft Defender for Endpoint alerts and incidents, classify them with evidence, and take the first response actions your playbook allows.

Level
Intermediate
Length
About 45 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026
  • Microsoft Defender for Endpoint

Skills you'll practise

  • Explain how alerts, incidents and device timelines relate in Defender for Endpoint.
  • Read an alert's process story and identify the malicious step and any persistence.
  • Classify an alert as true positive, informational/expected activity, or false positive, with evidence.
  • Choose an appropriate first response action (for example isolate device, stop and quarantine file) and escalate.

Course outline

  1. 1.Defender for Endpoint alerts: triage basicsVideo · 4 min
  2. 2.Alerts, incidents and the device timelineLesson · 8 min
  3. 3.Classifying alerts with evidenceLesson · 8 min
  4. 4.First response actionsLesson · 8 min
  5. 5.Defender for Endpoint alerts: triage basics: knowledge checkKnowledge check · 18 questions
  6. 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

  • Microsoft Learn: Investigate alerts in Microsoft Defender for Endpoint
  • Microsoft Learn: Incidents in Microsoft Defender XDR
  • Microsoft Learn: Take response actions on a device
  • Microsoft Learn: Take response actions on a file
  • Microsoft Learn: Classify and resolve alerts

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.