Microsoft Unified SecOps Platform
Fundamentals

Cases Overview

In brief

The documentation now states that MDTI projects are deprecated and directs users to link threat indicators to cases in the Microsoft Defender portal.

What Defender admins need to know

Administrators using projects should plan to organize and investigate indicators through cases instead.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Learn about the case management capabilities in the Defender portal for managing and standardizing unified security operations. author: mberdugo ms.author: monaberdugo ms.date: 05/04/202507/31/2026 ms.collection:

  • M365-security-compliance
  • tier1

Link indicators (preview)

Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat.

To link the case to IOCs, go to the Linked Objects tab in the Case page and select Indicators. Then, select the Add button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on Link.

Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat.

To link the case to IOCs, go to the Linked Objects tab in the Case page and select Indicators. Then, select the Add button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on Link.