Is that alert really of any value? If you have ATP I wouldn't focus on it much. Turn it off and run a daily report on any PE where DaysBeforeDetection = 0. Much more useful.
@countrybound I would agree with Daveb3d, that based on the description of the configuration of that sections of your environment, that particular rule does not sound to be suited/of much likely use to you. If you were to proceed as you've requested, it would make more sense to disable the rule for those systems, and proceed with an alternative like the one suggested.
Is the recommendation is to disable not to report from Access Protection Policy? Application team see these bunch of errors in Windows eventvwr. They are thinking its causing an issue. In Windows eventvwr that event is listed as an error instead of threat events.
Are you specifically looking to disable the event within Event viewer? If so then then you can change this in common policy.
That will disable the event from going to windows event viewer. If you are looking to disable the event for the specific rule, then you have to disable the complete rule.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA