Incident Navigate Triage
In brief
The Microsoft Sentinel incident navigation and triage page now introduces required roles and permissions and provides steps for navigating to and triaging incidents. Its date and authoring metadata were also updated.
What Defender admins need to know
No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Prerequisites
Before you investigate incidents, make sure you have the following roles and permissions.
The Microsoft Sentinel Responder role assignment is required to investigate incidents.
Learn more about roles in Microsoft Sentinel.
Navigate and triage incidents
Use the following steps to navigate to and triage incidents in Microsoft Sentinel.
From the Microsoft Sentinel navigation menu, under Threat management, select Incidents.
The Incidents page gives you basic information about all of your open incidents. For example:
@@ -5,11 +5,11 @@ ms.author: guywild author: guywi-ms ms.reviewer: mmagenheim ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 appliesto: - Microsoft Sentinel in the Azure portal ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 #Customer intent: As a security analyst, I want to learn the basics of navigating, triaging, and managing Microsoft Sentinel incidents in the Azure portal so that I can start investigating and responding to security incidents. --- @@ -19,6 +19,8 @@ This article describes how to navigate and run basic triage on your incidents in ## Prerequisites +Before you investigate incidents, make sure you have the following roles and permissions.+ - The [**Microsoft Sentinel Responder**](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-responder) role assignment is required to investigate incidents. Learn more about [roles in Microsoft Sentinel](roles.md).@@ -27,6 +29,8 @@ This article describes how to navigate and run basic triage on your incidents in ## Navigate and triage incidents +Use the following steps to navigate to and triage incidents in Microsoft Sentinel.+ 1. From the Microsoft Sentinel navigation menu, under **Threat management**, select **Incidents**. The **Incidents** page gives you basic information about all of your open incidents. For example: 