Create an incident report with Microsoft Copilot in Microsoft Defender
In brief
The article was rewritten for clarity, explicitly states that Security Copilot access is required, and clarifies that resolving an incident before report generation helps capture all actions. Links, metadata, and descriptions were also updated.
What Defender admins need to know
Administrators should note the access prerequisite and that unresolved incidents may produce incomplete action details. No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Create an incident report with Microsoft Copilot in Microsoft Defender
[!INCLUDE Microsoft Defender XDR rebranding]
Microsoft Security Copilot in the Microsoft Defender portal assistshelps security operations teams with writingwrite incident reports efficiently. Utilizingquickly. With Security Copilot's AI-powered data processing, security teamsCopilot, you can immediately create an incident reports withreport in just a click of a button in the Microsoft Defender portal.few clicks.
This guide listscovers the data in incident reports and contains steps onshows how to accessuse the Generate incident report capabilityfeature in the Microsoft Defender portal. This guideIt also includes information onexplains how to providegive feedback abouton the incident report generated report.by Copilot.
Before you begin
Incident report generation requires provisioned access to Security Copilot.
If you're new to Security Copilot, you should familiarize yourself with it by reading the following articles:
- What is Security Copilot?
- Understand authentication in Security Copilot
- Prompting in Security Copilot
A comprehensive and clear incident report is an essentiala key reference for security teams and security operations management.their managers. However, writing a comprehensivedetailed report with the important details present can be a time-consuming task for security operations teams. Collecting, organizing,takes time. Teams must collect, organize, and summarizing incident informationsummarize data from multiple sources requires focus and detailed analysis to create an information-rich report.many sources. With Copilot in Defender, security teamsyou can now instantly create an extensivea full incident report withinin the portal.portal right away.
While an incident summary provides an overview of an incident and how it happened, an incident report consolidates incident information from various data sources available in Microsoft Sentinel and Defender XDR.Defender. The Copilot-generated incident report also includes all analyst-driven steps and automated actions, the analysts involved in incident response, and the comments from the analysts. Whether security teams are using Microsoft Sentinel, Defender XDR,Defender, or both, all relevant incident data are added into the generated incident report.
Copilot generatesbuilds the incident report based on thefrom automatic and manual actions implemented, and the analysts'actions, plus analyst comments and notes posted innotes. To get the incident. You can review andbest results, follow the recommendations for incident report creation to ensure that Copilot creates a comprehensive incident report..
Security Copilot integration in Microsoft Defender
TheYou can generate incident report generation capabilityreports in Microsoft Defender is available for customers whoif you have provisioned access to Security Copilot.
Incident report generation isYou can also availablegenerate incident reports in the Security Copilot standalone portal throughportal. Use the Microsoft Defender XDR plugin, awhich is preinstalled Security Copilot integration thatand connects Copilot to Defender incident data. Learn more about preinstalled plugins in Security Copilot.
Key incident report features
- Investigation and remediation actions
- Follow up actions like recommendations, open issues, or next steps noted by the analysts in the incident logs
ActionsThe report includes actions like device isolation, disabling a user, and soft delete of emails are included in the incident report.emails. For a full list of actions included in the incident report,list, see the Microsoft Defender Action center. The Copilot-generated incident report also includes Microsoft Sentinel playbooks. that ran. Live response commands and response actions coming from public API sources or from custom detections are notaren't yet supported.
We recommend resolvingResolve the incident before you generate the report to viewcapture all actions that have been taken. Incidents that are not resolved will partially reflect the actions inactions. If the incident report.isn't resolved, the report might only show some of the actions.
Create an incident report
Export incident data to PDF
You can export the incident data to PDF to create a report that you can easily share with stakeholders. The exported incident data contains relevant information like the attack story, impacted assets, relevant alerts, and AI-generated content from Copilot, like the incident summary and incident report. With this capability,incident data export to PDF, security teams can quickly export moreshare incident information for post-incident discussions withinwith team members or with other stakeholders.
You can follow the steps in export incident data to PDF to generate the PDF.
Here are some recommendations to consider to ensure that Copilot generates a comprehensive and complete incident report:
- Classify and resolve the incident before generating the incident report.
- Ensure that you write and save comments in the Microsoft Sentinel activity log or in the Microsoft Defender incident activity log to include the comments in the incident report.
- Write comments using comprehensive and clear language. In-depth and clear comments provide better context about the response actions. See the following steps to know how to access the comments field:
- Add comments to incidents in the Microsoft Defender portal
- Add comments to incidents in Microsoft Sentinel
- For ServiceNow users, enable the Microsoft Sentinel and ServiceNow bi-directional sync to get more robust incident data.
- Copy the generated incident report and post it to the activity log in the Microsoft Defender portal to ensure that the incident report is saved in the incident page.
Sample prompt for incident report creation
In the Security Copilot standalone portal, you can use the followingthis prompt to create thean incident report:
- Generate the incident report for Defender incident {incident ID}.
Provide feedback
Your feedback helps improve Copilot. To share feedback, go to the bottom of the Copilot side panel and select the feedback icon
.
Related content
- Learn about other Security Copilot embedded experiences
- Privacy and data security in Security Copilot
[!INCLUDE Microsoft Defender XDR rebranding]
\ No newline at end of file
[!INCLUDE Microsoft Defender XDR rebranding]
@@ -11,26 +11,28 @@ ms.collection: - security-copilot - magic-ai-copilot ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.update-cycle: 180-days appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Create an incident report with Microsoft Copilot in Microsoft Defender [!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)] -[Microsoft Security Copilot](/security-copilot/microsoft-security-copilot) in the Microsoft Defender portal assists security operations teams with writing incident reports efficiently. Utilizing Security Copilot's AI-powered data processing, security teams can immediately create incident reports with a click of a button in the Microsoft Defender portal.+[Microsoft Security Copilot](/security-copilot/microsoft-security-copilot) in the Microsoft Defender portal helps security teams write incident reports quickly. With Security Copilot, you can create an incident report in just a few clicks. -This guide lists the data in incident reports and contains steps on how to access the **Generate incident report** capability in the Microsoft Defender portal. This guide also includes information on how to provide feedback about the generated report.+This guide covers the data in incident reports and shows how to use the **Generate incident report** feature in the Microsoft Defender portal. It also explains how to give feedback on the incident report generated by Copilot. <a name="know-before-you-begin"></a> ## Before you begin +Incident report generation requires provisioned access to Security Copilot.+ If you're new to Security Copilot, you should familiarize yourself with it by reading the following articles: - [What is Security Copilot?](/security-copilot/microsoft-security-copilot)@@ -39,17 +41,17 @@ If you're new to Security Copilot, you should familiarize yourself with it by re - [Understand authentication in Security Copilot](/security-copilot/authentication) - [Prompting in Security Copilot](/security-copilot/prompting-security-copilot) -A comprehensive and clear incident report is an essential reference for security teams and security operations management. However, writing a comprehensive report with the important details present can be a time-consuming task for security operations teams. Collecting, organizing, and summarizing incident information from multiple sources requires focus and detailed analysis to create an information-rich report. With Copilot in Defender, security teams can now instantly create an extensive incident report within the portal.+A clear incident report is a key reference for security teams and their managers. However, writing a detailed report takes time. Teams must collect, organize, and summarize data from many sources. With Copilot in Defender, you can create a full incident report in the portal right away. -While an [incident summary](security-copilot-m365d-incident-summary.md) provides an overview of an incident and how it happened, an incident report consolidates incident information from various data sources available in Microsoft Sentinel and Defender XDR. The Copilot-generated incident report also includes all analyst-driven steps and automated actions, the analysts involved in incident response, and the comments from the analysts. Whether security teams are using Microsoft Sentinel, Defender XDR, or both, all relevant incident data are added into the generated incident report.+While an [incident summary](security-copilot-m365d-incident-summary.md) provides an overview of an incident and how it happened, an incident report consolidates incident information from various data sources available in Microsoft Sentinel and Defender. The Copilot-generated incident report also includes all analyst-driven steps and automated actions, the analysts involved in incident response, and the comments from the analysts. Whether security teams are using Microsoft Sentinel, Defender, or both, all relevant incident data are added into the generated incident report. -Copilot generates the incident report based on the automatic and manual actions implemented, and the analysts' comments and notes posted in the incident. You can review and follow the [recommendations for incident report creation](security-copilot-m365d-create-incident-report.md#recommendations-for-incident-report-creation) to ensure that Copilot creates a comprehensive incident report.+Copilot builds the report from automatic and manual actions, plus analyst comments and notes. To get the best results, follow the [recommendations for incident report creation](security-copilot-m365d-create-incident-report.md#recommendations-for-incident-report-creation). ## Security Copilot integration in Microsoft Defender -The incident report generation capability in Microsoft Defender is available for customers who have provisioned access to Security Copilot. +You can generate incident reports in Microsoft Defender if you have access to Security Copilot. -Incident report generation is also available in the Security Copilot standalone portal through the Microsoft Defender XDR plugin, a preinstalled Security Copilot integration that connects Copilot to Defender incident data. Learn more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins).+You can also generate incident reports in the Security Copilot standalone portal. Use the Microsoft Defender XDR plugin, which is preinstalled and connects Copilot to Defender incident data. Learn more about [preinstalled plugins in Security Copilot](/security-copilot/manage-plugins#preinstalled-plugins). <a name="key-features"></a> ## Key incident report features@@ -64,9 +66,9 @@ Copilot in Defender creates an incident report containing the following informat - Investigation and remediation actions - Follow up actions like recommendations, open issues, or next steps noted by the analysts in the incident logs -Actions like device isolation, disabling a user, and soft delete of emails are included in the incident report. For a full list of actions included in the incident report, see the [Action center](m365d-action-center.md). The incident report also includes [Microsoft Sentinel playbooks ran](/azure/sentinel/automate-responses-with-playbooks). [Live response commands](/defender-endpoint/live-response) and response actions coming from public API sources or from custom detections are not yet supported.+The report includes actions like device isolation, disabling a user, and soft delete of emails. For a full list, see the [Microsoft Defender Action center](m365d-action-center.md). The Copilot-generated incident report also includes [Microsoft Sentinel playbooks](/azure/sentinel/automate-responses-with-playbooks) that ran. [Live response commands](/defender-endpoint/live-response) and actions from public API sources or custom detections aren't yet supported. -We recommend resolving the incident to view all actions that have been taken. Incidents that are not resolved will partially reflect the actions in the incident report.+Resolve the incident before you generate the report to capture all actions. If the incident isn't resolved, the report might only show some of the actions. ### Create an incident report @@ -92,7 +94,7 @@ To create an incident report with Copilot in Defender, perform the following ste ### Export incident data to PDF -You can export the incident data to PDF to create a report that you can easily share with stakeholders. The exported incident data contains relevant information like the attack story, impacted assets, relevant alerts, and AI-generated content from Copilot, like the incident summary and incident report. With this capability, security teams can quickly export more incident information for post-incident discussions within team members or with other stakeholders.+You can export the incident data to PDF to create a report that you can easily share with stakeholders. The exported incident data contains relevant information like the attack story, impacted assets, relevant alerts, and AI-generated content from Copilot, like the incident summary and incident report. With incident data export to PDF, security teams can quickly share incident information for post-incident discussions with team members or other stakeholders. You can follow the steps in [export incident data to PDF](manage-incidents.md#export-incident-data-to-pdf) to generate the PDF. @@ -101,25 +103,25 @@ You can follow the steps in [export incident data to PDF](manage-incidents.md#ex Here are some recommendations to consider to ensure that Copilot generates a comprehensive and complete incident report: - Classify and resolve the incident before generating the incident report.-- Ensure that you write and save comments in the Microsoft Sentinel activity log or in the [Microsoft Defender XDR incident activity log](manage-incidents.md#view-the-activity-log-of-an-incident) to include the comments in the incident report.+- Ensure that you write and save comments in the Microsoft Sentinel activity log or in the [Microsoft Defender incident activity log](manage-incidents.md#view-the-activity-log-of-an-incident) to include the comments in the incident report. - Write comments using comprehensive and clear language. In-depth and clear comments provide better context about the response actions. See the following steps to know how to access the comments field: - [Add comments to incidents in the Microsoft Defender portal](manage-incidents.md#add-comments-to-an-incident) - Add comments to incidents in Microsoft Sentinel-- For ServiceNow users, [enable the Microsoft Sentinel and ServiceNow bi-directional sync](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-introducing-microsoft-sentinel-solution-for/ba-p/3692840) to get more robust incident data.+- For ServiceNow users, enable the [Microsoft Sentinel and ServiceNow bi-directional sync](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-introducing-microsoft-sentinel-solution-for/ba-p/3692840) to get more robust incident data. - Copy the generated incident report and post it to the activity log in the Microsoft Defender portal to ensure that the incident report is saved in the incident page. ## Sample prompt for incident report creation -In the Security Copilot standalone portal, you can use the following prompt to create the incident report:+In the Security Copilot standalone portal, use this prompt to create an incident report: - *Generate the incident report for Defender incident {incident ID}.* > [!TIP]-> When generating incident reports in the Security Copilot portal, Microsoft recommends including the word ***Defender*** in your prompts to ensure that the incident report creation capability delivers the results.+> Include the word ***Defender*** in your prompts. This helps Security Copilot use the right capability and return the correct results. ## Provide feedback -Microsoft highly encourages you to provide feedback to Copilot, as it's crucial for a capability's continuous improvement. To provide feedback, navigate to the bottom of the Copilot side panel and select the feedback icon .+Your feedback helps improve Copilot. To share feedback, go to the bottom of the Copilot side panel and select the feedback icon . <a name="see-also"></a> ## Related content@@ -127,4 +129,4 @@ Microsoft highly encourages you to provide feedback to Copilot, as it's crucial - [Learn about other Security Copilot embedded experiences](/security-copilot/experiences-security-copilot) - [Privacy and data security in Security Copilot](/copilot/security/privacy-data-security) -[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]\ No newline at end of file+[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)] 