MC1481318: Microsoft Defender XDR Adds Detection Source Selection to Alert Tuning Rules

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
45
0 25 50 75 100
MODERATE IMPACT • ASSESS BUSINESS IMPACT
Recommended Action:
Take a look and decide whether this affects your tenant, users or support teams.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Security TeamsMicrosoft 365 AdminsTenant AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This is a new capability in Microsoft Defender XDR adding detection source selection for alert tuning rules, giving admins finer control over rule scope. Admins should review and adjust existing alert tuning rules where more specific scoping is desired. Impact is primarily operational for security and Defender administrators; end user experience is not affected. Rollout dates are set for later in 2026, so planning urgency is moderate.
58
🛡️ Admin Impact
20
👥 User Impact
45
⚡ Urgency
46
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Defender XDR alert tuning rules will soon support detection source selection, giving admins finer control over which sources their rules apply to.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review existing alert tuning rules and update detection source selections if you want more targeted control.
📅

ROLLOUT TIMELINE

Upcoming:
Mid-October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender XDR: Detection source support in alert tuning rules
Message ID: MC1481318

[What and why]

We are introducing detection source selection for alert tuning rules in Microsoft Defender XDR. This update enables alert tuning rules to be scoped to specific detection sources, providing more granular control over how alert tuning rules are applied.

As part of this update, alert tuning rules will apply to the detection sources selected for each rule. Existing rules that are not updated will apply to all detection sources under their selected service sources, including custom detections.

[Rollout schedule]

  • Public Preview (Worldwide): Rollout begins in mid-October 2026 and is expected to complete in early November 2026.
    • Note: Detection source selection will become available in mid-October 2026, and configured detection source selections will take effect in early November 2026.
  • General Availability (Worldwide): Rollout begins in mid-November 2026 and is expected to complete in early December 2026.
    • Note: Detection source selection will become available in mid-November 2026, and configured detection source selections will take effect in early December 2026.

[Impact on your organization]

Who is affected

  • Organizations that use alert tuning rules in Microsoft Defender XDR.

Platforms and services

  • Microsoft Defender XDR

What will happen

  • Alert tuning rules will be configurable to apply to specific detection sources and apply only to the detection sources selected for each rule.
  • If not updated, existing alert tuning rules will apply to all detection sources under their selected service sources, including custom detections.

Detection source selection

detection sources in alert properties

[Action required and recommendations]

No action is required if existing rules should apply to all detection sources under their selected service sources, including custom detections. Otherwise, we recommend that you review existing alert tuning rules and update the detection source selections as needed.

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update