Microsoft Defender false positives

Most alerts close as benign. Proving it still costs you an hour each.

Defender is doing its job: it flags what looks wrong. In a typical tenant the large majority of alerts close as benign - after someone has spent an hour collecting the context to prove it. 1Security links every Defender alert to the account behind it, what that account can reach, whether today is normal for it, and what it actually touched. Close the false positive with proof in minutes. Escalate the real one with evidence attached.

The problem

Every Defender alert costs an investigation. Most deserve a glance.

A high-severity Defender alert names an account. Now the real work starts: what is this account, what can it reach, is this activity unusual for it, and did anything sensitive actually move? Collecting the answers by hand means permissions in one place, sign-ins in another, mailbox access in a third and activity history in a fourth. An hour later you have a shrug and a closed ticket.

Because that hour is expensive, teams triage by instinct. Familiar account, working hours, probably fine - dismissed. In a tenant that gets dozens of Defender alerts a week, the one that mattered gets the same instinct treatment, because nothing on the alert itself separates it from the noise.

Tuning Defender rules does not fix this. Fewer alerts still cost an hour each. What fixes it is making one alert cheap to judge: the account, its reach, its baseline and its history one click from the alert, so a false positive closes in two minutes with evidence, and a real one is escalated in five.

In practice

Triage in four questions, each one click.

The same Defender alert, worked in 1Security with everything on one screen.

  1. 01

    Open the alert and see who this is

    Defender and Sentinel alerts land in 1Security's Security alerts list already linked to the user, group, mailbox or app they concern. One click opens the account: its groups, licenses, MFA registration, sign-in state, admin roles, and a 30-day trend of what it does on a normal day.

  2. 02

    Check whether today is normal for it

    Anomaly baselines compare today with the median of the account's own trailing 30 days. A finance clerk downloading 40 files reads as routine when their baseline is 38 - and as an incident when it is 3. If an anomaly episode is open for this account, it is right there next to the alert.

  3. 03

    See what it could reach

    The permission graph resolves the account's effective access: every site, file and mailbox, through direct grants, sharing links, nested groups and inheritance. It is common for an ordinary account to reach hundreds of thousands of files. A blast-radius question that used to take half a day takes ten minutes.

  4. 04

    See what it actually touched, then decide

    Up to three years of Activity logs filtered to the account, with device and location on every event - the downloads, the shares, the mailbox reads, the sign-in from a hosting network. Real threat: escalate with the rows attached, or stage a fix (revoke links, remove access, disable) behind a review window. False positive: close with proof instead of a shrug.

What makes it work

Context is a platform feature, not an analyst habit.

Three parts of the platform do the heavy lifting behind this workflow. Each is documented in depth.

  • Alerts with entities attached

    Defender and Sentinel alerts land linked to the users, groups, emails and apps they concern - the pivot to investigation is one click, not a search.

    Explore the alerts tool
  • Effective access, resolved

    The permission graph answers what the flagged account could actually reach - nested groups, sharing links, mailbox delegates and inheritance included.

    Explore access management
  • Three years of memory

    What the account did before and after the alert, with device and origin on every event - three years of history instead of 180 days, on standard licenses.

    Explore the audit tool

FAQ

Common questions.

Does 1Security replace Microsoft Defender?

No. Defender keeps detecting; 1Security makes its alerts cheap to judge. Your Defender and Sentinel alerts appear inside 1Security linked to the entities they concern, and the triage context - reach, baseline, history - lives around them.

Do I have to tune Defender rules to see fewer false positives?

No rule changes are needed. The alerts stay as they are; what changes is the cost of judging one. When a verdict takes two minutes with evidence, false positives stop consuming shifts even if their count never moves. Once you see which accounts and behaviours generate the benign ones, tuning becomes an informed choice rather than a guess.

What licenses does this require?

Security alert ingestion uses your existing Defender setup. Everything 1Security adds - the permission graph, baselines, three years of history - runs on standard Microsoft 365 licenses from Business Basic upward, with read-only consent. No E5, no Entra P2, no agent to install.

How fast is the context available after we connect?

Alerts, accounts and effective access appear as soon as the first scan completes - the same day for most tenants. Activity history builds from the day you connect and is kept for up to three years; behavioural baselines stay quiet for the first 14 days on purpose, then compare every alert against a real normal.

Give every Defender alert its context.

Connect read-only, and the next Defender alert arrives with the account's reach, baseline and history one click away - so it closes or escalates in minutes.

Or keep triaging severity strings by instinct.