Microsoft Defender for Cloud Security Alerts are still open while link in Defender XDR is already resolved

Francis Arvin Hallare 25 Reputation points
2025-02-04T12:43:45.0866667+00:00

Our team observed that there are open or active alerts in Microsoft Defender for Cloud while its corresponding incident in Defender XDR is already resolved. We assume that it is the corresponding alert in Defender XDR since when we click the link in Microsoft Defender for Cloud it redirected to it. Maybe a sync issue?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,499 questions
{count} votes

Accepted answer
  1. SrideviM 235 Reputation points Microsoft Vendor
    2025-02-20T08:57:58.2833333+00:00

    Hello @Francis Arvin Hallare,

    There’s no direct fix for this, but there are ways to avoid it happening as often. Since Defender XDR tends to process alerts from Defender for Endpoint first, the best approach is to make sure alerts from both sources are properly linked.

    You can check the incident correlation rules in XDR to see if it’s grouping related alerts correctly. Also, switching to the tenant-based Defender for Cloud connector (instead of the older subscription-based one) helps with better syncing between Defender for Cloud and XDR. If alerts in Defender for Cloud are still staying open after XDR marks the incident as resolved, you might need to close them manually or set up an automated playbook using Logic Apps to handle it for you.

    Hope this helps!

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.