Microsoft Sentinel
Incidents and response

Incident Navigate Triage

In brief

The Microsoft Sentinel incident navigation and triage page now introduces required roles and permissions and provides steps for navigating to and triaging incidents. Its date and authoring metadata were also updated.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you investigate incidents, make sure you have the following roles and permissions.

Navigate and triage incidents

Use the following steps to navigate to and triage incidents in Microsoft Sentinel.

  1. From the Microsoft Sentinel navigation menu, under Threat management, select Incidents.

    The Incidents page gives you basic information about all of your open incidents. For example: