Microsoft Sentinel
Cloud and workloads

Ingest Microsoft Defender for Cloud Incidents with Microsoft Defender XDR Integration

In brief

The page was refreshed with updated metadata, clearer wording about automation rules and the legacy subscription-based connector, and a consolidated link for Defender for Cloud alerts and incidents in Microsoft Defender XDR.

What Defender admins need to know

Review the guidance if you use this integration, particularly the recommendations to disable the legacy connector and duplicate alert-generating rules. No mandatory administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Ingest Microsoft Defender for Cloud incidentsIncidents with Microsoft Defender XDR integrationIntegration description: Learn how using Microsoft Defender for Cloud's integration with Microsoft Defender XDR lets you ingest Microsoft Defender for Cloud incidents through Microsoft Defender XDR. This lets you add Defender for Cloud incidents to your Microsoft Sentinel incidents queue while seamlessly applying Defender XDR's strengths to help investigate all your cloud workload security incidents. ms.author: guywild author: guywi-ms ms.reviewer: idpelleg ms.topic: how-to ms.date: 06/15/07/02/2026 ai-usage: ai-assisted ms.custom: msecd-doc-authoring-10141016

#Customer intent: As a security analyst, I want to integrate Microsoft Defender for Cloud with Microsoft Defender XDR so that I can ingest and synchronize incidents and alerts into Microsoft Sentinel for comprehensive threat detection and response.

Choose how to use this integration and the new connector

  • If you have enabled Defender XDR integration, but you only want to receive Defender for Cloud alerts but not incidents, you can use automation rules to immediately close Defender for Cloud incidents as they arrive.

    If that'susing automation rules to close incidents is not an adequate solution, or if you still want to collect alerts from Defender for Cloud on a per-subscription basis, you can completely opt-out of the Defender for Cloud integration in the Microsoft Defender XDR portal, and then use the legacy, subscription-based version of the Defender for Cloud connector to receive those alerts.

Set up the integration in Microsoft Sentinel

After you enable incident integration in your Microsoft 365 Defender connector, enable the new Tenant-based Microsoft Defender for Cloud (Preview) connector. This connector is available through the Microsoft Defender for Cloud solution, version 3.0.0, in the Content Hub. If you have an earlier version of this solution, you can upgrade the solution in the Content Hub.

If you had previously enabled the legacy, subscription-based Defender for Cloud connector (which will beis displayed as Subscription-based Microsoft Defender for Cloud (Legacy)), then you're advised to disable it to prevent duplication of alerts in your logs.

If you have any Scheduled or Microsoft Security analytics rules that create incidents from Defender for Cloud alerts, you're encouraged to disable these rules, since you'll be receiving ready-made incidents created by—and (and synchronized with—with) Microsoft 365 Defender.

If there are specific types of Defender for Cloud alerts for which you don't want to create incidents, you can use automation rules to close incidents created from those alerts immediately, or you can use the built-in tuning capabilities in the Microsoft 365 Defender portal.

Next steps

For more information about the Microsoft Defender for Cloud integration with Microsoft Defender XDR, see the following resources.

Related content