From fda3bc6f9afe2918232d30af06b75cdbf4acde62 Mon Sep 17 00:00:00 2001 From: Ben Date: Mon, 14 Dec 2020 18:20:13 +0200 Subject: [PATCH] Update review-alerts.md --- .../threat-protection/microsoft-defender-atp/review-alerts.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md index 28ce3b1696..d32c73580f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md @@ -46,7 +46,7 @@ Clicking on an alert's name in Defender for Endpoint will land you on its alert ![An alert page when you first land on it](images/alert-landing-view.png) -Note the detection status for your alert. Blocked, prevented, or remediated means actions were already taken by Defender for Endpoint. +Note the detection status for your alert. Blocked, or prevented means actions were already taken by Defender for Endpoint. Start by reviewing the *automated investigation details* in your alert's [details pane](#take-action-from-the-details-pane), to see which actions were already taken, as well as reading the alert's description for recommended actions. ![A snippet of the details pane with the alert description and automatic investigation sections highlighted](images/alert-air-and-alert-description.png)