List of triggers for different severity levels for alerts.

Jvlivemicro 0 Reputation points
2025-08-06T13:55:11.5333333+00:00

Hello, I would to like to point out that I can’t find full documentation of what determines the severity level for every single alert that is ingested into Microsoft Defender XDR or Sentinel. I would like to know every single trigger for High, medium and low severity. I feel like this is definitely something they could include in the SC-200 Course and documentation for both Defender XDR and Sentinel.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2025-08-11T10:22:05.4966667+00:00

    Not a full answer but, in Sentinel you can look a the baseline level for each Detection as they are in the GitHub https://github.com/Azure/Azure-Sentinel/tree/master/Solutions There are many 100s if not 1000s. So at least for these you can see the default level Microsoft provided as guidance.
    However businesses will override these or some of these, based on your own adoption/policies.

    Defender XDR custom detections are defined by you, but the others are set by Microsoft.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.