The correct answer is B. the Microsoft Defender portal. Microsoft Purview DLP policies can generate alerts when rule conditions are matched. Microsoft states that DLP alerts can be investigated and managed in both Microsoft Defender XDR and the Microsoft Purview portal, but the Defender XDR dashboard is the recommended location for investigating and managing DLP alerts. That fits the requirement to view alert details and understand how the alert relates to other alerts, because Defender provides the incident and alert investigation experience. Microsoft Intune is used for endpoint and app management. Microsoft Entra is used for identity and access administration. The Microsoft 365 admin center is used for tenant administration and reporting, not DLP alert correlation.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit