Microsoft Defender for OneSOC
Accessibility Conformance Report published by Microsoft
Conformance by level
Reported by the vendor. WCAG Level AA is the benchmark referenced by ADA Title II, Section 508 and the European Accessibility Act; Level AAA is optional and often left unevaluated.
Level A — 32 criteria
- Supports
- 16
- Partially supports
- 11
- Does not support
- 0
- Not applicable
- 5
- Not evaluated
- 0
Level AA — 24 criteria
- Supports
- 11
- Partially supports
- 10
- Does not support
- 0
- Not applicable
- 3
- Not evaluated
- 0
Level AAA — 31 criteria
- Supports
- 0
- Partially supports
- 0
- Does not support
- 0
- Not applicable
- 0
- Not evaluated
- 31
Source: Download the original report from Microsoft (Word document). Or browse all of Microsoft's reports on Microsoft's own site.
These figures are extracted from that document. They are the vendor's own statements, not an independent assessment, and automated extraction can misread a table.
All reported criteria (87)
| Criterion | Name | Level | Conformance | Remarks from vendor |
|---|---|---|---|---|
| 1.1.1 | Non-text Content | A | Partially Supports | - On the User Page under Incidents & Alerts, the screen reader does not announce “opens in a new tab” for menu items in the “Search for name or ID” combo box.- On the File Page, the screen reader does not announce the visually available “opens in a new tab” icon for the “View messages” link in the dialog. |
| 1.2.1 | Audio-only and Video-only (Prerecorded) | A | Not Applicable | |
| 1.2.2 | Captions (Prerecorded) | A | Not Applicable | |
| 1.2.3 | Audio Description or Media Alternative (Prerecorded) | A | Not Applicable | |
| 1.3.1 | Info and Relationships | A | Partially Supports | - On the Alerts page, the screen reader does not announce the position of “Search Suggestions”.- In the Associated Alerts dialog, the heading “Submit items to Microsoft for review” is not programmatically defined.- On the Alerts page, invalid searches in the Categories filter combo box are announced as “No categories found not selected 1 of 1” instead of a proper status message.- On the Alerts page, invalid searches in the Tags combo box are announced incorrectly instead of with an appropriate status message.- In the Associated Alerts dialog, the group label “Select scope to apply to” is not announced for radio buttons.- In Advanced Hunting, the Schema Reference search field announces incorrect and duplicate search result information.- In Advanced Hunting, elements with ARIA roles that require child roles are missing in the Filters section.- On the User Page under Incidents & Alerts, elements marked as presentational incorrectly include global ARIA or tabindex attributes.- On the User Page under Incidents & Alerts, the screen reader does not announce X-axis time information when navigating the graph.- On the User Page under Incidents & Alerts, tooltip information is not announced when focus lands on the Refresh control.- In Advanced Hunting, grouping labels for list items in the Load Sample Queries combo box are not announced (except for the Endpoints group).- In the Results tab of Advanced Hunting, the tooltip “Cannot Edit in Read-Only Editor” is not announced when attempting to edit.- In the Streaming API, the grouping label “Events Types (0/27)” is not announced when focus moves to the checkbox.- In Detection Rules Triggered Alerts, the position of “Search Suggestions” is not announced.- In Advanced Hunting, the OAuthAppId combo box announces “list item 1 of 1” even when no visual list item exists.- In Advanced Hunting, entering 1–2 characters in the Device Name combo box does not fetch items visually, but the screen reader announces “list item 1 of 1”.- In Advanced Hunting, contextual information for selected items in the Device Name combo box is not provided in the Device Name filter dialog.- On the Detection Rules page, the banner card heading “Quickly optimize your rules” is not programmatically defined.- In Advanced Hunting, the visual text “Onboard to Sentinel Graph to enable this capability” is not defined under a heading level.- In Advanced Hunting, entire sections are announced as “figure” when focus lands.- In Advanced Hunting, no region or complementary landmark is defined for the graph section.- In Advanced Hunting Query Resources, sorting information is not announced when column headers are invoked.- In Advanced Hunting, elements with ARIA roles that require child roles are missing in the menu bar.- In Advanced Hunting, the “Updated by” label is not associated with the search field.- In Advanced Hunting, checkboxes in the Customize Columns dialog are announced incorrectly as “unavailable”.- In Advanced Hunting Custom Detection, the error message “This section contains misconfigured fields …” is not descriptive and is not associated with section buttons.- In Advanced Hunting, the “View details” dialog name is not defined under a heading level.- In the Results tab of Advanced Hunting, info icon tooltips are not announced when revealed.- In Detection Rules, elements with ARIA roles that require child roles are missing in the Search field of the menu bar.- On the User Page under Incidents & Alerts, the screen reader incorrectly announces “no color selected” for text color and background color controls.- On the User Page under Incidents & Alerts Activity Log, tooltip information for “Lateral Movement” is not announced.- In Alert Tuning, headings such as “Alert types,” “Conditions,” and “Action” in the Tune Alert dialog are not programmatically defined.- In Investigation, ARIA roles requiring child roles are missing in the More Options submenu of the Document Review Request dialog.- In Investigation, the Alert ID link in the Emails table dialog is not associated with its label.- On the File Page, the heading “Ask Defender Experts inquiry created” is not programmatically defined.- In Alert Tuning, the search result count in the Select a filter popup is announced incorrectly.- In Alert Tuning, the informative text “Alert suppression will be applied based on User Sid” is not announced when focus lands on the User edit field. |
| 1.3.2 | Meaningful Sequence | A | Supports | |
| 1.3.3 | Sensory Characteristics | A | Partially Supports | - In Microsoft Defender, in Investigation under Threat Management, no tooltip is defined for “Submit for analysis” and “Manage indicator” submenu in URLs table dialog.- In Microsoft Defender, on Alerts page, at 400% zoom, no visual label or tooltip is defined for “Alert Service Settings” control. |
| 1.4.1 | Use of Color | A | Supports | |
| 1.4.2 | Audio Control | A | Not Applicable | |
| 2.1.1 | Keyboard | A | Partially Supports | - In Microsoft Defender Threat Management Investigation, table headers in Mailboxes table are not draggable using keyboard.- In Microsoft Defender Threat Management Investigation, single pointer alternative is not provided for table headers in Mailboxes tab.- In Microsoft Defender Threat Management Investigation, data in Common Entity column gets truncated in Correlation Reasons table at 100% zoom.- In Microsoft Defender Threat Management Investigation, tooltip for selected entity in Entity combo box is not keyboard accessible.- In Microsoft Defender Alerts page, at 400% zoom, unable to access Alert search suggestion with keyboard.- In Microsoft Defender Alerts page, at 400% zoom, tooltip for truncated user email list in Assign To combo box is not keyboard accessible.- In Microsoft Defender Alerts page, Correlation Reasons table column headers are not resizable with keyboard.- In Microsoft Defender Alerts page, table column headers in Actions Taken section are not resizable with keyboard.- In Microsoft Defender Alerts page, label text in Inspect Record pane gets truncated at 100% zoom.- In Microsoft Defender User Page under Incidents & Alerts, at 400% zoom, tooltip for truncated menu items is not keyboard accessible in Incident Assignment combo edit field.- In Microsoft Defender User Page under Incidents & Alerts, table rows under Incidents and Alerts tab are not fully visible.- In Microsoft Defender User Page under Incidents & Alerts, controls in Users and Mailboxes table rows are not accessible via keyboard.- In Microsoft Defender User Page under Incidents & Alerts, keyboard users cannot access tooltip info in “35 Incidents” static text.- In Microsoft Defender Advanced Hunting Query Builder, menu bar controls are not keyboard accessible.- In Microsoft Defender Advanced Hunting Query Builder, tooltip for selected Device in Device Name combo box is not keyboard accessible in filter popup.- In Microsoft Defender Advanced Hunting Results tab, keyboard users cannot read all content in Last Run Status section.- In Microsoft Defender Advanced Hunting, keyboard focus does not move to all interactive controls and menu items in left pane.- In Microsoft Defender Advanced Hunting Detection Rule Triggered Alert, at 100% zoom, menu item tooltips in Alert Type and Entities combo boxes are not keyboard accessible.- In Microsoft Defender User Page under Incidents & Alerts, Expand/Collapse control inside Audits checkbox is not keyboard accessible in content popup.- In Microsoft Defender User Page under Incidents & Alerts, Save button in Enter Link popup is not keyboard accessible.- In Microsoft Defender User Page under Incidents & Alerts Activity Log, comment edit field is not keyboard accessible.- In Microsoft Defender Alerts page, tooltip for selected Alert Type in Alert Type combo box is not keyboard accessible in Filters control.- In Microsoft Defender Advanced Hunting – Workspace Selector, at 400% zoom, keyboard users cannot view the entire table row data in the Workspace Selector dialog. |
| 2.1.2 | No Keyboard Trap | A | Supports | |
| 2.1.4 | Character Key Shortcuts | A | Supports | |
| 2.2.1 | Timing Adjustable | A | Supports | |
| 2.2.2 | Pause, Stop, Hide | A | Supports | |
| 2.3.1 | Three Flashes or Below Threshold | A | Supports | |
| 2.4.1 | Bypass Blocks | A | Supports | |
| 2.4.2 | Page Titled | A | Supports | |
| 2.4.3 | Focus Order | A | Partially Supports | - In Microsoft Defender Threat Management Investigation, “View incident queue” button receives keyboard focus twice.- In Microsoft Defender Alerts page, keyboard focus is lost after saving/closing “Enable all AAD Identity Protection alerts” dialog.- In Microsoft Defender Associated Alerts dialog, keyboard focus shifts to Close button after uploading file in “Submit items to Microsoft for review” dialog.- In Microsoft Defender Alerts page, keyboard focus does not land on first interactive element when Alerts detail webpage loads.- In Microsoft Defender Alerts page, keyboard focus does not move to displayed side pane after activating user link.- In Microsoft Defender Advanced Hunting Schema Reference, keyboard focus is lost when activating a row in Schema Reference dialog.- In Microsoft Defender Advanced Hunting Filters, incorrect focus order after activating Apply button in DeviceProcessEvents filter.- In Microsoft Defender User Page under Incidents & Alerts, keyboard focus is lost after activating Save button in Manage Incident dialog.- In Microsoft Defender Advanced Hunting Query Builder, keyboard focus is lost after selecting “Query in builder” from Create New submenu.- In Microsoft Defender Advanced Hunting, keyboard focus is lost after activating Hunting Graph control.- In Microsoft Defender Advanced Hunting Inspect Record, incorrect focus order after adding a sub-group; focus skips to previous filter section.- In Microsoft Defender Advanced Hunting Results tab, keyboard focus is lost after deleting a table row using Delete button; subsequent Tab moves focus out of UI.- In Microsoft Defender Advanced Hunting Results tab, keyboard focus is lost after activating Delete button; subsequent Tab moves focus out of UI.- In Microsoft Defender Detection Rules, screen reader does not announce Expand/Collapse state when toggling left pane (focus issue).- In Microsoft Defender Advanced Hunting Custom Detection, keyboard focus moves incorrectly to Query Editor after deleting View Rule dialog.- In Microsoft Defender Advanced Hunting, keyboard focus does not return to triggering control after closing Save Function dialog.- In Microsoft Defender Advanced Hunting Results tab, keyboard focus is lost after activating Close button in full-screen mode; subsequent Tab moves focus out of UI.- In Microsoft Defender Advanced Hunting Results tab, keyboard focus is lost after selecting any menu item in Chart Type combo box; subsequent Tab moves focus out of UI.- In Microsoft Defender Advanced Hunting, keyboard focus is lost after activating Create New Graph menu item; menu remains visible and Tab moves focus out of UI.- In Microsoft Defender Advanced Hunting Results tab, keyboard focus is lost after activating Apply button in Customize Columns dialog; subsequent Tab moves focus out of UI.- In Microsoft Defender Detection Rules, keyboard focus does not land on first interactive element in Detail Detection Rule page after opening from table dialog.- In Microsoft Defender Advanced Hunting Create New tab, keyboard focus does not shift to Create New submenu when activated from More Tabs.- In Microsoft Defender User Page under Incidents & Alerts, keyboard focus does not land on expected control after adding all filters using Add button.- In Microsoft Defender Alert Tuning, keyboard focus moves out of Manage Alert dialog after updating comment, even though dialog remains open.- In Microsoft Defender Alert Tuning, keyboard focus is lost after toggling rule On/Off in Alert Tuning table dialog.- In Microsoft Defender Alert Tuning, keyboard focus skips to Add Filter after adding multiple filters using Select a Filter dropdown.- In Microsoft Defender Alert Tuning, keyboard focus skips to previous filter section after adding a sub-group.- In Microsoft Defender Incidents – Activities, keyboard focus loss occurs after invoking “Collapse in MAP / Expand in MAP” control present in dialog. |
| 2.4.4 | Link Purpose (In Context) | A | Supports | |
| 2.5.1 | Pointer Gestures | A | Supports | |
| 2.5.2 | Pointer Cancellation | A | Supports | |
| 2.5.3 | Label in Name | A | Partially Supports | - In Microsoft Defender Advanced Hunting Query Builder, visual name and accessible name are not the same for the “View in” combo field.- In Microsoft Defender Advanced Hunting Query Builder, visual name and accessible name are not the same for the “Device Name” combo box in Device Name filter. |
| 2.5.4 | Motion Actuation | A | Supports | |
| 3.1.1 | Language of Page | A | Supports | |
| 3.2.1 | On Focus | A | Partially Supports | - In Microsoft Defender Alerts page, the “Enable all AAD Identity Protection alerts” dialog opens automatically when the “All alerts” radio button is selected. |
| 3.2.2 | On Input | A | Partially Supports | - In Microsoft Defender Alert Tuning, keyboard focus skips to “Select a filter” combo box in Level 1 after resetting any filter subgroup.- In Microsoft Defender Alert Tuning, keyboard focus is lost and “Select a filter” control disappears after dismissing the popup with Esc key.- In Microsoft Defender Alert Tuning, applied filter resets and focus incorrectly lands on “Any” button when Select a Filter popup is collapsed using Esc key.- In Microsoft Defender Alerts page, activating “More option” in Joni Sherman using keyboard opens Joni Sherman dialog instead of submenu. |
| 3.2.6 | Consistent Help | A | Supports | |
| 3.3.1 | Error Identification | A | Partially Supports | - In Microsoft Defender Associated Alerts dialog, no error message is displayed when uploading a duplicate file in “Submit items to Microsoft for review” dialog.- In Microsoft Defender Associated Alerts dialog, client error message appears but is not descriptive when saving “Add evidence (IOCs) as indicators” dialog.- In Microsoft Defender User Page under Incidents & Alerts, error message is not displayed when creating a filter set with an existing name.- In Microsoft Defender Streaming API settings, error message displayed upon submitting “Add new Streaming API settings” dialog does not accurately indicate what is wrong.- In Microsoft Defender Advanced Hunting Query Builder, no input validation provided for Email Address field in Email Address filter dialog.- In Microsoft Defender Advanced Hunting Filters, error message is not provided when entering incorrect email address in email combo box.- In Microsoft Defender Incidents – Task Investigate, visual heading level is not defined for “Trace user activity,” “Search mailbox rules,” “Run mailbox rule query,” and “Report suspicious activity.” |
| 3.3.2 | Labels or Instructions | A | Partially Supports | - In Microsoft Defender Alert Tuning, no visual label provided for “Group operator AND/OR” combo box in Edit Rule dialog.- In Microsoft Defender Alerts page, visual label or time range value is not visible by default; only chevron is visible for Time Range dropdown.- In Microsoft Defender Alerts page, “Change list spacing” dropdown options lack visible labels and accessible names in Actions Taken section.- In Microsoft Defender User Page under Incidents & Alerts, persistent label is not provided for “Search for name or ID” field in Incidents & Alerts tab.- In Microsoft Defender Advanced Hunting Query Builder, persistent label is not defined for “Load sample queries” combo box.- In Microsoft Defender Advanced Hunting Query Builder, no visual label provided for “Group operator AND/OR” combo box.- In Microsoft Defender Advanced Hunting, persistent labels are not provided for Find and Replace edit fields.- In Microsoft Defender User Page under Incidents & Alerts Activity Log, persistent label is not provided for “Comment” field in Activity Log dialog. |
| 3.3.7 | Redundant Entry | A | Supports | |
| 4.1.1 | Parsing | A | Not Applicable | |
| 4.1.2 | Name, Role, Value | A | Partially Supports | - In Microsoft Defender Threat Management Investigation, Remove button control in Entity combo box lacks accessible name.- In Microsoft Defender Action Center Investigation, Export email submissions button missing accessible name.- In Microsoft Defender Alerts, expanded/collapsed state of query results table not announced after first toggle.- In Microsoft Defender Alerts, non-interactive controls incorrectly assigned button role in Impacted assets column.- In Microsoft Defender Alerts, ARIA role elements in Tags column missing required child roles.- In Microsoft Defender Alerts, screen reader does not announce state when expanding/collapsing “View 10 similar alerts” info button.- In Microsoft Defender SOC Optimization, screen reader not announcing state for Alert graph expand/collapse.- In Microsoft Defender Advanced Hunting (Schema Reference), info icons not announcing name, role, or tooltip information.- In Microsoft Defender Advanced Hunting (Query Builder), search edit field in Select filter pop-up has incorrect aria-label.- In Microsoft Defender Incidents & Alerts, Close button in All Evidence dialog lacks discernible text.- In Microsoft Defender Incidents & Alerts, nested interactive controls in filter submenu cause screen reader focus issues.- In Microsoft Defender Advanced Hunting (Query Builder), Load sample queries combo box missing accessible name.- In Microsoft Defender Advanced Hunting (Query Builder), button in sample size submenu lacks discernible text.- In Microsoft Defender Advanced Hunting (Query History), non-interactive controls incorrectly assigned button role in Time column.- In Microsoft Defender Streaming API Settings, Close button lacks discernible text.- In Microsoft Defender Advanced Hunting (Dialog), Close button lacks discernible text.- In Microsoft Defender Advanced Hunting (Entity Mapping), info buttons lack discernible text.- In Microsoft Defender Advanced Hunting (Results Tab), info icon lacks discernible text.- In Microsoft Defender Advanced Hunting (Results Tab), Customize columns control lacks discernible text.- In Microsoft Defender Advanced Hunting (Menu), incorrect state announced after activating Create new.- In Microsoft Defender Advanced Hunting (Results Tab), Export button lacks accessible name.- In Microsoft Defender Triggered Alerts Table, Workspace column cells lack accessible names.- In Microsoft Defender SOC Optimization Pane, non-interactive Data types incorrectly assigned button role.- In Microsoft Defender Incidents & Alerts, screen reader fails to announce selected state for font color buttons.- In Microsoft Defender Incidents & Alerts, Black button in font color popup lacks accessible name. |
| 1.2.4 | Captions (Live) | AA | Not Applicable | |
| 1.2.5 | Audio Description (Prerecorded) | AA | Not Applicable | |
| 1.3.4 | Orientation | AA | Supports | |
| 1.3.5 | Identify Input Purpose | AA | Supports | |
| 1.4.3 | Contrast (Minimum) | AA | Partially Supports | - In Microsoft Defender Threat Management Investigation, in dark mode, contrast ratio is 3.4:1 for “malicious” text in mailboxes table side panel.- In Microsoft Defender Threat Management Investigation, in dark mode, contrast ratio is 3.3:1 for “View in the Submissions page” link in Evidence table dialog.- In Microsoft Defender Alerts page, in dark mode, contrast ratio is 2.2:1 for error message “The end date you’ve chosen…” on invalid date selection.- In Microsoft Defender Alerts page, in dark mode, contrast ratio is 2:1 for text “The custom detection rule that triggered this alert has been deleted” in Alert table dialog.- In Microsoft Defender Associated Alerts dialog, in dark mode, contrast ratio is 3.3:1 for “Learn more about submission” and “Privacy statement” links.- In Microsoft Defender Advanced Hunting FRE screen, in dark mode, contrast ratio is 2.02:1 for “Next” button text.- In Microsoft Defender Home Banner card, in dark mode, insufficient contrast ratio for text “Take your security to the next level…” due to multicolored background.- In Microsoft Defender Home Banner card, in dark mode, insufficient contrast ratio for “Connect Microsoft Sentinel…” text and “Set up trial” button due to multicolored background.- In Microsoft Defender User Page Incidents & Alerts, in dark mode, contrast ratio is 2.2:1 for error message in Custom Time Range dialog.- In Microsoft Defender User Page Incidents & Alerts, in dark mode, contrast ratio is 3.7:1 for “suggested assignments” text in incident assignment expanded menu.- In Microsoft Defender Advanced Hunting Custom Sample Size dialog, in dark mode, contrast ratio is 2.2:1 for error message “Value must be an integer between 1 to 30000.”- In Microsoft Defender Advanced Hunting Query History, in high contrast Aquatic/Desert themes, less contrast ratio for most text in Query column over selected table row.- In Microsoft Defender Streaming API dialog, in dark theme, contrast ratio for Cancel button is 1.2:1 (less than required 4.5:1).- In Microsoft Defender Advanced Hunting, in high contrast modes, link in Name column becomes difficult to see when row is selected due to low contrast.- In Microsoft Defender Advanced Hunting, in high contrast desert mode, selected row text in Frequency column cell data is not visible due to contrast ratio 1.6:1.- In Microsoft Defender Advanced Hunting Results tab, in high contrast aquatic/desert mode, links in selected table row have contrast ratios 1.391:1 and 1.038:1.- In Microsoft Defender Settings – XDR Associated Alerts, placeholder text in “Explain in more detail” edit field within “Submit feedback to Microsoft” dialog has insufficient contrast ratio (1.5:1).- In Microsoft Defender Settings – XDR Associated Alerts, less contrast ratio (2.6:1) for radio button and checkbox labels when unselected in “Submit feedback to Microsoft” dialog. |
| 1.4.4 | Resize text | AA | Partially Supports | - In Microsoft Defender Alert Tuning, at 200% zoom, label text in “Successful suppressions rule creation” dialog gets truncated.- In Microsoft Defender Threat Management Investigation, at 200% zoom, complete graph is not visible in Investigation Graph tab.- In Microsoft Defender Threat Management Investigation, at 200% zoom, list option in Entity combo box gets truncated.- In Microsoft Defender Alerts page, at 200% zoom, Move Alerts control and Alert Count overlap, and Customize Columns control goes hidden.- In Microsoft Defender Associated Alerts dialog, at 200% zoom, label text in “Add evidence (IOCs) as indicators” dialog gets truncated.- In Microsoft Defender Advanced Hunting Query Resources, at 200% zoom, half of the table on the right side is truncated.- In Microsoft Defender User Page under Incidents & Alerts, at 200% zoom, status bar text is truncated and overlapped when focus lands on “Most recent incidents and alerts” combo box.- In Microsoft Defender Advanced Hunting Query History, at 200% zoom, command bar controls overlap and truncate in Query History tab.- In Microsoft Defender Advanced Hunting Custom Detection, at 200% zoom, graphic image in Hunting Graph section overlaps with disabled “Search with Predefined scenarios” and “View details” controls.- In Microsoft Defender Advanced Hunting Results tab, at 200% zoom in reflow mode, Customize Columns menu item under More Actions cannot be activated using keyboard or mouse. |
| 1.4.5 | Images of Text | AA | Supports | |
| 1.4.10 | Reflow | AA | Partially Supports | - In Microsoft Defender Threat Management Investigation, at 400% zoom, list option in Entity combo box gets truncated.- In Microsoft Defender Alerts page, at 400% zoom, Search suggestion list gets cut off on the right side.- In Microsoft Defender Associated Alerts dialog, at 400% zoom, label text in “Add evidence (IOCs) as indicators” dialog gets truncated.- In Microsoft Defender Sentinel SOC Optimization Content Hub, in High Contrast Aquatic/Desert mode, links in Content Name and Created Content columns not visible on selected row.- In Microsoft Defender User Page under Incidents & Alerts, at 400% zoom in reflow, message bar text and map overlap on the page.- In Microsoft Defender User Page under Incidents & Alerts, at 400% zoom, table rows under Mailboxes section are truncated.- In Microsoft Defender User Page under Incidents & Alerts, at 400% zoom, expanded search menu items truncated and inaccessible.- In Microsoft Defender Advanced Hunting Query Builder, at 400% zoom, horizontal scrollbar appears for entire section.- In Microsoft Defender Advanced Hunting Query Builder, at 400% zoom, IsOwnedThread combo box list opens behind dialog.- In Microsoft Defender Advanced Hunting Custom Detection, at 400% zoom, horizontal scrollbar appears for entire Alert Settings step.- In Microsoft Defender Advanced Hunting Custom Detection, at 400% zoom, graphic image in Hunting Graph section overlaps with Tab controls.- In Microsoft Defender Advanced Hunting, at 400% zoom, More Actions menu items truncated and not visible when focused.- In Microsoft Defender Advanced Hunting, at 400% zoom in reflow, placeholder text and controls not fully visible in Find and Replace popup.- In Microsoft Defender Advanced Hunting Results tab, at 400% zoom in reflow, Share Link menu item under More Actions cannot be activated via keyboard or mouse.- In Microsoft Defender Advanced Hunting Results tab, at 400% zoom in reflow, Customize Columns menu item under More Actions cannot be activated via keyboard or mouse.- In Microsoft Defender Advanced Hunting Detection Rule Triggered Alert, at 400% zoom, list options in Policy/Policy Rule combo box truncated.- In Microsoft Defender Advanced Hunting Detection Rule Triggered Alert, at 400% zoom, Custom Time Range dialog overlaps with More Actions submenu.- In Microsoft Defender Home Action Center card, at 400% zoom, heading text “2 pending actions Last 30 days” truncated.- In Microsoft Defender Advanced Hunting Custom Detection, at 400% zoom, View Rule dialog overlaps with More Actions submenu.- In Microsoft Defender Settings Endpoints Advanced Features, at 400% zoom in reflow, page content does not reflow properly; text breaks with one character per line.- In Microsoft Defender Sentinel Content Hub SIEM Migration wizard, at 400% zoom, Description content not visible and Note section disoriented in Configuration Rules pane. |
| 1.4.11 | Non-text Contrast | AA | Partially Supports | - In Microsoft Defender Home Banner Card, in Dark Mode, the contrast ratio for the “Close” button is 1:1 (less than required 3:1).- In Microsoft Defender User Page under Incidents & Alerts, in High Contrast modes, keyboard focus indicator for controls in “Incident name” column has insufficient contrast.- In Microsoft Defender Advanced Hunting Custom Detection, in High Contrast Aquatic and Desert themes, keyboard focus indicator has insufficient contrast (1.5:1 and 1.4:1) over selected checkboxes in Specific Device Group combo box.- In Microsoft Defender Advanced Hunting, in normal mode, contrast ratio is 1.329:1 for the Clear Text button at the search edit field.- In Microsoft Defender User Page under Incidents & Alerts, in Dark Mode, selected control is not visually distinguishable. |
| 1.4.12 | Text Spacing | AA | Partially Supports | - In Microsoft Defender Threat Management Investigation, after applying text spacing, resize functionality does not work to adjust column width with keyboard.- In Microsoft Defender Threat Management Investigation, after applying text spacing, list option in Entity combo box gets truncated.- In Microsoft Defender User Page under Incidents & Alerts, after applying text spacing, text in message bar is not fully visible within Incidents & Alerts tab.- In Microsoft Defender User Page under Incidents & Alerts, after applying text spacing, text in “Manage incidents & 6 months” combo box overlaps. |
| 1.4.13 | Content on Hover or Focus | AA | Supports | |
| 2.4.5 | Multiple Ways | AA | Supports | |
| 2.4.6 | Headings and Labels | AA | Partially Supports | - In Microsoft Defender Advanced Hunting Query Builder, no descriptive name is defined for the “Sample Size” button in Query Builder section.- In Microsoft Defender Advanced Hunting Query Builder, label “Remove” is not defined for the remove button control for selected Device Name in Device Name filter. |
| 2.4.7 | Focus Visible | AA | Partially Supports | - In Microsoft Defender Advanced Hunting Custom Detection, in High Contrast Aquatic and Desert modes, keyboard focus indicator is only partially visible on checkboxes in Specific Device Group combo box in Scope step. |
| 2.4.11 | Focus Not Obscured (Minimum) | AA | Partially Supports | - In Microsoft Defender Alerts page, at 400% zoom, keyboard-focused list item is obscured in Incident Name or ID combo box in Move Alert to Another Incident dialog.- In Microsoft Defender User Page under Incidents & Alerts, at 400% zoom, keyboard-focused menu items are not visible on screen in Incident Assignment filter combo box.- In Microsoft Defender Advanced Hunting Filters, at 400% zoom in reflow mode, keyboard-focused items are not visible in suggestion list.- In Microsoft Sentinel – Table Management, the “Workspace” table does not automatically scroll, causing keyboard-focused row controls to be partially hidden off-screen.- In Microsoft Defender Incidents – Activities, keyboard-focused node is not visible on the screen while navigating within the “MAP” section. |
| 2.5.7 | Dragging Movements | AA | Partially Supports | - In Microsoft Defender Threat Management Investigation, a single-pointer alternative is not provided for dragging table headers in the Mailboxes tab. |
| 2.5.8 | Target Size (Minimum) | AA | Supports | |
| 3.1.2 | Language of Parts | AA | Supports | |
| 3.2.3 | Consistent Navigation | AA | Supports | |
| 3.2.4 | Consistent Identification | AA | Supports | |
| 3.3.3 | Error Suggestion | AA | Supports | |
| 3.3.4 | Error Prevention (Legal, Financial, Data) | AA | Not Applicable | |
| 3.3.8 | Accessible Authentication (Minimum) | AA | Supports | |
| 4.1.3 | Status Messages | AA | Partially Supports | - Microsoft Defender – Advanced Hunting – Query Builder (Filters): Screen reader not announcing any search result information on entering a keyword.- Microsoft Defender – Advanced Hunting – Query Resources: Screen reader does not announce “No data” information when all toggle buttons are turned off at the graph.- Microsoft Defender – Advanced Hunting – Custom Sample Size: Screen reader fails to announce error status message on entering invalid value in “Insert the number of results…” spin button in “Custom sample size” dialog.- Microsoft Defender – Advanced Hunting: Screen reader not announcing any search result information while searching for valid/invalid data.- Microsoft Defender – Advanced Hunting – Custom Detection: Screen reader fails to announce alert information in “Review and Create” step in “Custom Detection” wizard.- Microsoft Defender – User Page – Incidents & Alerts: Screen reader is not announcing “loading” and “comment added” information after activating Save button.- Microsoft Defender – Security – Alert Tuning – Report Incident: Screen reader does not provide the thank you message information on submitting the feedback.- Microsoft Defender – OneSoc – Search (Files) – File Page: Screen reader is not reading the “Submitting” status after selecting Submit button in the “Ask Defender Experts” dialog. |
| 1.2.6 | Sign Language (Prerecorded) | AAA | Not Evaluated | |
| 1.2.7 | Extended Audio Description (Prerecorded) | AAA | Not Evaluated | |
| 1.2.8 | Media Alternative (Prerecorded) | AAA | Not Evaluated | |
| 1.2.9 | Audio-only (Live) | AAA | Not Evaluated | |
| 1.3.6 | Identify Purpose | AAA | Not Evaluated | |
| 1.4.6 | Contrast (Enhanced) | AAA | Not Evaluated | |
| 1.4.7 | Low or No Background Audio | AAA | Not Evaluated | |
| 1.4.8 | Visual Presentation | AAA | Not Evaluated | |
| 1.4.9 | Images of Text (No Exception) | AAA | Not Evaluated | |
| 2.1.3 | Keyboard (No Exception) | AAA | Not Evaluated | |
| 2.2.3 | No Timing | AAA | Not Evaluated | |
| 2.2.4 | Interruptions | AAA | Not Evaluated | |
| 2.2.5 | Re-authenticating | AAA | Not Evaluated | |
| 2.2.6 | Timeouts | AAA | Not Evaluated | |
| 2.3.2 | Three Flashes | AAA | Not Evaluated | |
| 2.3.3 | Animation from Interactions | AAA | Not Evaluated | |
| 2.4.8 | Location | AAA | Not Evaluated | |
| 2.4.9 | Link Purpose (Link Only) | AAA | Not Evaluated | |
| 2.4.10 | Section Headings | AAA | Not Evaluated | |
| 2.4.12 | Focus Not Obscured (Enhanced) | AAA | Not Evaluated | |
| 2.4.13 | Focus Appearance | AAA | Not Evaluated | |
| 2.5.5 | Target Size | AAA | Not Evaluated | |
| 2.5.6 | Concurrent Input Mechanisms | AAA | Not Evaluated | |
| 3.1.3 | Unusual Words | AAA | Not Evaluated | |
| 3.1.4 | Abbreviations | AAA | Not Evaluated | |
| 3.1.5 | Reading Level | AAA | Not Evaluated | |
| 3.1.6 | Pronunciation | AAA | Not Evaluated | |
| 3.2.5 | Change on Request | AAA | Not Evaluated | |
| 3.3.5 | Help | AAA | Not Evaluated | |
| 3.3.6 | Error Prevention (All) | AAA | Not Evaluated | |
| 3.3.9 | Accessible Authentication (Enhanced) | AAA | Not Evaluated |
Is this your product? If this report is out of date or misrepresented, we will correct or remove it. Contact us to claim this listing.
Get told when this changes
This report is dated December 12, 2025. An ACR can be quietly replaced at any time, and the published date is the only signal a buyer gets. We will email you when this one is updated.
Double opt-in — we email you once to confirm, and send nothing until you do. One-click unsubscribe on every message. We store your address and what you are watching, nothing else. Privacy.