MC783216 - "Investigation priority score increase" Policy to be retired

Message Center

This announcement expired on Nov 11, 2024 and is no longer active in Message Center.

Summary

The "Investigation priority score increase" policy in Microsoft Defender for Cloud Apps will be retired between June and September 2024 due to high false positives and limited value. Administrators should use the Advanced Hunting query as an alternative.

Last Updated

Aug 15, 2024

Published Apr 22, 2024

View version history

Service

Microsoft Defender XDR

Tag

Major change
Updated message
User impact
Admin impact
Retirement

More information

Updated August 15, 2024: We have updated the rollout timeline below. Thank you for your patience.

We will be gradually retiring the "Investigation priority score increase" policy support from Microsoft Defender for Cloud Apps between June and July 2024.

After careful analysis and consideration, we have decided to deprecate it due to the high rate of false positives associated with this alert, which we found was not contributing effectively to the overall security of your organization. Our research indicated that this feature was not adding significant value and was not aligned with our strategic focus on delivering high-quality, reliable security solutions. We are committed to continuously improving our services and ensuring that they meet your needs and expectations.

When this will happen:

We will begin rolling this out in late June 2024 (previously early June) and expect to complete by late September 2024 (previously late July).

How this will affect your organization:

SOC administrators and analysts will no longer be able to access, manage and use "Investigation priority score increase" alerts in "Microsoft Defender for Cloud Apps", when this change is implemented.

What you need to do to prepare:

If this policy type is used in your organization and is needed, we recommend using the Advanced Hunting query in the resource linked below.

Please use the following resources for additional information:

Version history

4 versions tracked

Updated 3 times since Apr 22, 2024. Microsoft Message Center only ever shows the current version; this archive preserves the history.

Compare any two versions

From
To
  1. Aug 15, 2024 · 11:40 PMLatest · v4

    Changed: Services

  2. Aug 15, 2024 · 11:40 PMv3

    Changed: Body, End date

  3. Jun 19, 2024 · 06:33 PMv2

    Changed: Body, Tags

  4. Apr 22, 2024 · 09:54 PMOriginal · v1

    Changed: Initial version