Microsoft Sentinel
Incidents and response

Create Incident Manually

In brief

The page date and custom metadata were updated, and the Microsoft Sentinel API description was clarified to identify the Incidents operation group and its get, create, update, and delete operations.

What Defender admins need to know

Administrators can use the refreshed page and clearer API wording when managing incident-creation procedures.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

After onboarding Microsoft Sentinel to the Microsoft Defender portal, manually created incidents aren't synchronized with the Defender portal, though they can still be viewed and managed in Microsoft Sentinel in the Azure portal, and through Logic Apps and the API.