Solution

MSP alert management for Microsoft 365 security

Configure notification policies and alert groups to deliver monitoring events to the right MSP team members. Control which findings and scan changes generate notifications.

Alert management components

Notification policies

Define conditions for when monitoring and assessment events generate notifications.

Alert groups

Assign team members to groups that receive alerts for specific customers or severity levels.

Email routing

Deliver monitoring notifications to configured email recipients in policies.

Activity log

Organization events recorded when alert settings and policies change.

Reducing alert noise

Policy-based filtering

Notification policies limit alerts to the event types and severities your team needs to act on.

Group-based routing

Route alerts to specialists responsible for specific customers rather than broadcasting to the entire organization.

Findings triage first

Combine alert routing with portfolio finding review so high-severity issues are handled before lower-priority noise accumulates.

Alert routing workflow

Monitoring detects change
Scheduled assessments or asset scans produce new or changed results.
Policy evaluates event
Notification policy determines whether an alert is generated.
Group receives alert
Configured alert group members are notified, including by email where enabled.
Team reviews in workspace
Recipients triage findings and monitoring context in the customer workspace.

Related pages

Frequently asked questions

Next steps

Configure alert management for your MSP team

MSP Security Alert Management | SecurityScore.me