Microsoft Defender XDR
General

Manage Incidents

In brief

The article was updated with a new date, clearer incident-lifecycle wording, a Microsoft Defender portal access note, expanded KQL terminology, and more precise instructions for exporting an Incident report as a PDF from the Copilot side panel.

What Defender admins need to know

Administrators can use the revised guidance to locate incident-management tasks and the Copilot PDF export option more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

search.appverid:

  • MOE150
  • MET150 ms.date: 06/16/07/02/2026 appliesto:
  • Microsoft Defender XDR
  • Microsoft Sentinel in the Microsoft Defender portal

[!INCLUDE Microsoft Defender XDR rebranding]

Incident management is critical to ensuring that incidents are named, assigned, and tagged to optimize time in your incident workflow and more quickly contain and address threats. To perform these tasks, you need access to the Microsoft Defender portal with an appropriate role assigned through Microsoft Defender XDR role-based access control (RBAC).

To manage your incidents in the Microsoft Defender portal, use the quick launch and go to Investigation & response > Incidents & alerts > Incidents.

:::image type="content" source="./media/manage-incidents/incidents-queue.png" alt-text="Screenshot showing the incident queue and quick launch pane in the Microsoft Defender portal." lightbox="./media/manage-incidents/incidents-queue.png":::

This article shows yousection explains how to perform various incident management tasks associated with different stages in anMicrosoft Defender across the incident's lifecycle.

To open an incident or alert on demand for an investigation or operational workflow, see Manually create an incident or alert in Microsoft Defender.

Access the Manage incident pane

Most of these tasks are accessible from the Manage incident pane for an incident. You can reach this pane from any of several locations. The analysis includes details such as:

  • A high-level summary of the incident and investigation process including actions and activities done by the analyst.
  • Detailed step by step-by-step log and KQLKusto Query Language (KQL) queries run during the investigation process.

Use the generated analyst notes to train new analysts, conduct audits, support investigations, hand off work to teammates, or feed AI models and tools.

The export to PDF function is also available in the Copilot side panel. When you select the More actions ellipsis (...) on the upper right corner of the incidentIncident report results card,card in the Copilot side panel, you can choose Export incident as PDF.

:::image type="content" source="media/manage-incidents/export-incident-more-actions1.png" alt-text="Screenshot of additional actions in the incident report results card.":::