STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must alert administrators on policy violations defined for endpoints.

DISA Rule

SV-272882r1119408_rule

Vulnerability Number

V-272882

Group Title

SRG-APP-000207

Rule Version

MSDE-00-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least a Security Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. Click "+Add notification rule".
3. Enter Name, Notification settings, and Recipients as defined by the AO.
4. Click "Save". Repeat as necessary.
5. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
6. Click "+Add notification rule".
7. Enter Name, Notification settings, and Recipients as defined by the AO.
8. Click "Save". Repeat as necessary.

Check Contents

Access the MDE portal as a user with at least a Security Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. For each defined Notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the authorizing official (AO).
- Verify the Recipient Emails are assigned as defined by the AO.
3. Click "Cancel".
4. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
5. For each defined notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the AO.
- Verify the Recipient Emails are assigned as defined by the AO.
6. Click "Cancel".

If Settings >> Endpoints >> Email notifications (under Permissions) >> Alerts does not display rules as defined by the AO, this is a finding.

If Settings >> Endpoints >> Email notifications (under Permissions) >> Vulnerabilities does not display rules as defined by the AO, this is a finding.

When selecting each rule individually, if the Notification Settings and Recipient Emails are not as defined by the AO, this is a finding.

Vulnerability Number

V-272882

Documentable

False

Rule Version

MSDE-00-000100

Severity Override Guidance

Access the MDE portal as a user with at least a Security Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. For each defined Notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the authorizing official (AO).
- Verify the Recipient Emails are assigned as defined by the AO.
3. Click "Cancel".
4. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
5. For each defined notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the AO.
- Verify the Recipient Emails are assigned as defined by the AO.
6. Click "Cancel".

If Settings >> Endpoints >> Email notifications (under Permissions) >> Alerts does not display rules as defined by the AO, this is a finding.

If Settings >> Endpoints >> Email notifications (under Permissions) >> Vulnerabilities does not display rules as defined by the AO, this is a finding.

When selecting each rule individually, if the Notification Settings and Recipient Emails are not as defined by the AO, this is a finding.

Check Content Reference

M

Target Key

5693