List of triggers for different severity levels for alerts.

Jvlivemicro 5 Reputation points
2025-08-06T13:55:11.5333333+00:00

Hello, I would to like to point out that I can’t find full documentation of what determines the severity level for every single alert that is ingested into Microsoft Defender XDR or Sentinel. I would like to know every single trigger for High, medium and low severity. I feel like this is definitely something they could include in the SC-200 Course and documentation for both Defender XDR and Sentinel.

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Sreetheja Adusumilli 325 Reputation points Microsoft External Staff Moderator
    2025-08-21T17:58:11.7333333+00:00

    Hello Jvlivemicro,

    Thanks for posting your question in Microsoft Q&A!

    About Microsoft Defender XDR and Azure Sentinel decide whether an alert is High, Medium, or Low severity, and if there’s a complete list of triggers for each level.

    The severity of an alert depends on two main things:

    • What kind of activity triggered the alert. Some activities, like seeing known malware or ransomware, are serious and get a High severity. Others, like unusual sign-ins or minor suspicious actions, might be Medium or Low.
    • How confident Microsoft is that the alert shows a real threat. Alerts with strong evidence get higher severity, while those that might be false alarms or less clear get lower severity.

    Examples:

    • High severity means something very suspicious or dangerous happened, like a malware infection or a successful exploit.
    • Medium severity means something odd or suspicious that could be a threat, but more checking is needed.
    • Low severity means something minor or informational, like a blocked attack or routine admin action.

    Microsoft doesn’t publish a full list of all triggers and their severities because the system constantly updates with new threat intelligence and detections.

    Here are some helpful Microsoft docs if you want to learn more:

    Kindly let us know if the above helps or you need further assistance on this issue.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.