Microsoft Defender XDR
Incidents and response

Create an incident report with Microsoft Copilot in Microsoft Defender

In brief

The article was rewritten for clarity, explicitly states that Security Copilot access is required, and clarifies that resolving an incident before report generation helps capture all actions. Links, metadata, and descriptions were also updated.

What Defender admins need to know

Administrators should note the access prerequisite and that unresolved incidents may produce incomplete action details. No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create an incident report with Microsoft Copilot in Microsoft Defender

[!INCLUDE Microsoft Defender XDR rebranding]

Microsoft Security Copilot in the Microsoft Defender portal assistshelps security operations teams with writingwrite incident reports efficiently. Utilizingquickly. With Security Copilot's AI-powered data processing, security teamsCopilot, you can immediately create an incident reports withreport in just a click of a button in the Microsoft Defender portal.few clicks.

This guide listscovers the data in incident reports and contains steps onshows how to accessuse the Generate incident report capabilityfeature in the Microsoft Defender portal. This guideIt also includes information onexplains how to providegive feedback abouton the incident report generated report.by Copilot.

Before you begin

Incident report generation requires provisioned access to Security Copilot.

If you're new to Security Copilot, you should familiarize yourself with it by reading the following articles:

A comprehensive and clear incident report is an essentiala key reference for security teams and security operations management.their managers. However, writing a comprehensivedetailed report with the important details present can be a time-consuming task for security operations teams. Collecting, organizing,takes time. Teams must collect, organize, and summarizing incident informationsummarize data from multiple sources requires focus and detailed analysis to create an information-rich report.many sources. With Copilot in Defender, security teamsyou can now instantly create an extensivea full incident report withinin the portal.portal right away.

While an incident summary provides an overview of an incident and how it happened, an incident report consolidates incident information from various data sources available in Microsoft Sentinel and Defender XDR.Defender. The Copilot-generated incident report also includes all analyst-driven steps and automated actions, the analysts involved in incident response, and the comments from the analysts. Whether security teams are using Microsoft Sentinel, Defender XDR,Defender, or both, all relevant incident data are added into the generated incident report.

Copilot generatesbuilds the incident report based on thefrom automatic and manual actions implemented, and the analysts'actions, plus analyst comments and notes posted innotes. To get the incident. You can review andbest results, follow the recommendations for incident report creation to ensure that Copilot creates a comprehensive incident report..

Security Copilot integration in Microsoft Defender

TheYou can generate incident report generation capabilityreports in Microsoft Defender is available for customers whoif you have provisioned access to Security Copilot.

Incident report generation isYou can also availablegenerate incident reports in the Security Copilot standalone portal throughportal. Use the Microsoft Defender XDR plugin, awhich is preinstalled Security Copilot integration thatand connects Copilot to Defender incident data. Learn more about preinstalled plugins in Security Copilot.

Key incident report features

  • Investigation and remediation actions
  • Follow up actions like recommendations, open issues, or next steps noted by the analysts in the incident logs

ActionsThe report includes actions like device isolation, disabling a user, and soft delete of emails are included in the incident report.emails. For a full list of actions included in the incident report,list, see the Microsoft Defender Action center. The Copilot-generated incident report also includes Microsoft Sentinel playbooks. that ran. Live response commands and response actions coming from public API sources or from custom detections are notaren't yet supported.

We recommend resolvingResolve the incident before you generate the report to viewcapture all actions that have been taken. Incidents that are not resolved will partially reflect the actions inactions. If the incident report.isn't resolved, the report might only show some of the actions.

Create an incident report

Export incident data to PDF

You can export the incident data to PDF to create a report that you can easily share with stakeholders. The exported incident data contains relevant information like the attack story, impacted assets, relevant alerts, and AI-generated content from Copilot, like the incident summary and incident report. With this capability,incident data export to PDF, security teams can quickly export moreshare incident information for post-incident discussions withinwith team members or with other stakeholders.

You can follow the steps in export incident data to PDF to generate the PDF.

Here are some recommendations to consider to ensure that Copilot generates a comprehensive and complete incident report:

  • Classify and resolve the incident before generating the incident report.
  • Ensure that you write and save comments in the Microsoft Sentinel activity log or in the Microsoft Defender incident activity log to include the comments in the incident report.
  • Write comments using comprehensive and clear language. In-depth and clear comments provide better context about the response actions. See the following steps to know how to access the comments field:
  • For ServiceNow users, enable the Microsoft Sentinel and ServiceNow bi-directional sync to get more robust incident data.
  • Copy the generated incident report and post it to the activity log in the Microsoft Defender portal to ensure that the incident report is saved in the incident page.

Sample prompt for incident report creation

In the Security Copilot standalone portal, you can use the followingthis prompt to create thean incident report:

  • Generate the incident report for Defender incident {incident ID}.

Provide feedback

Your feedback helps improve Copilot. To share feedback, go to the bottom of the Copilot side panel and select the feedback icon Screenshot of the Copilot in Defender feedback control used to submit feedback on generated results.

Related content

[!INCLUDE Microsoft Defender XDR rebranding] \ No newline at end of file [!INCLUDE Microsoft Defender XDR rebranding]