Microsoft Sentinel
Cloud and workloads

Create Incidents From Alerts

In brief

The article now specifies that Microsoft Defender XDR incident integration or onboarding Sentinel to the Defender portal causes Defender XDR to correlate incidents, and clarifies the Microsoft security data connector section and Azure account link.

What Defender admins need to know

Administrators can use the updated conditions to determine whether this Sentinel guidance applies; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

author: guywi-ms ms.reviewer: idpelleg ms.topic: how-to ms.date: 06/15/07/02/2026 ms.custom:

  • msecd-doc-authoring-10141016
  • mvc
  • sfi-image-nochange ai-usage: ai-assisted

    In these scenarios,If you enabled Microsoft Defender XDR incident integration or onboarded Microsoft Sentinel to the Microsoft Defender portal, Microsoft Defender XDR correlates alerts into incidents generated in Microsoft services.

    If you use incident creation rules for other Microsoft security solutions or products not integrated into Defender XDR, such as Microsoft Purview Insider Risk Management, and you plan to onboard to the Defender portal, replace your incident creation rules with scheduled analytics rules.

Connect your security solution by installing the appropriate solution from the Content Hub in Microsoft Sentinel and setting up the data connector. For more information, see Discover and manage Microsoft Sentinel out-of-the-box content and Microsoft Sentinel data connectors.

Enable automatic incident generation in a Microsoft security data connector

The most direct way to automatically create incidents from alerts generated from Microsoft security solutions is to configure the solution's data connector to create incidents:

If you don't see the Create incidents – Recommended section, you most likely have enabled incident integration in your Microsoft Defender XDR connector, or you have onboarded Microsoft Sentinel to the Defender portal.

In either case,If you have enabled incident integration in your Microsoft Defender XDR connector or onboarded Microsoft Sentinel to the Defender portal, this article does not apply to your environment, since your incidents are created by the Microsoft Defender correlation engine instead of by Microsoft Sentinel.

Create incident creation rules from a Microsoft Security template

Use the following resources to continue setting up and learning Microsoft Sentinel: