Microsoft Defender XDR will add six new built-in alert tuning rules for Microsoft Defender for Endpoint starting February 8, 2026, to reduce low-priority alerts. Rules are visible for review until February 18, then activate by default but can be disabled anytime by admins. No action needed for default use.
Introduction
Microsoft Defender XDR is adding six new Microsoft-curated built-in alert tuning rules for Microsoft Defender for Endpoint (MDE) to help reduce low-priority endpoint alerts reaching your queues.
When this will happen:
How this affects your organization:
Who is affected: Admins using Microsoft Defender XDR with MDE.
What will happen:
What you can do to prepare:
Learn more
Compliance considerations:
No compliance considerations identified; review as appropriate for your organization.