Manage Security Incidents
In brief
The incidents article now provides clearer steps for finding and managing incidents, improves screenshot descriptions, clarifies incident and alert wording, and updates the next-steps link.
What Defender admins need to know
No administrator action is required; the updates make incident guidance easier to follow and improve accessibility.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Triaging and investigating security alerts can be time consuming for even the most skilled security analysts. For many, it's hard to know where to begin.
Defender for Cloud uses analytics to connect information between distinct security alerts. For alert details, see Security alerts in Defender for Cloud and Manage and respond to security alerts. Using these connections,connections between related security alerts, Defender for Cloud provides a single view of an attack campaign and its related alerts to help you understand attacker actions and affected resources.
This page provides an overview of incidents in Defender for Cloud.
Manage security incidents
Perform the following steps to find and manage security incidents in Defender for Cloud:
On Defender for Cloud's security alerts page, use the Add filter button to filter by alert name to the alert name Security incident detected on multiple resources.
:::image type="content" source="media/incidents/locating-incidents.png" alt-text="Locating the incidents on the security alerts page in Microsoft Defender for Cloud.":::
To view details of an incident, select one from the list. A side pane appears with more details about the incident.
:::image type="content" source="media/incidents/incident-quick-peek.png" alt-text="
SideScreenshot of the side pane showing incident detailsof the incident.such as severity, status, and related alerts in Microsoft Defender for Cloud.":::To view more details, select View full details.
The left pane of the security incident page shows high-level information about the security incident: title, severity, status, activity time, description, and the affected resource. Next to the affected resource you can see the relevant Azure tags. Use
thesethe Azure tags shown next to the affected resource to infer the organizational context of the resource when investigating the alert.The right pane includes the Alerts tab with the security alerts that were correlated as part of this incident.
[](media/incidents/incident-take-action-tab.png#lightbox)
To switch to the **Take action** tab, select the tab or select the **Take action** button at the bottom of the right pane. Use this tab to take further actions such as:
- *Mitigate the threat* - provides manual remediation steps for this security incident
- *Prevent future attacks* - provides security recommendations to help reduce the attack surface, increase security posture, and prevent future attacks
- *Trigger automated response* - provides the option to trigger a Logic App as a response to this security incident
- *Suppress similar alerts* - provides the option to suppress future alerts with similar characteristics if the alert isn’t relevant for your organization
- To remediate the threats in the incident, follow the remediation steps provided with each alert.
Next stepsteps
[!div class="nextstepaction"] Manage and respond to security alerts
@@ -2,8 +2,8 @@ title: Manage Security Incidents description: Triage and investigate security incidents with correlated alerts and analytics in Microsoft Defender for Cloud to understand attack campaigns and affected resources. ms.topic: how-to-ms.date: 05/28/2026-ms.custom: sfi-image-nochange+ms.date: 07/03/2026+ms.custom: sfi-image-nochange, msecd-doc-authoring-1013 #customer intent: As a security analyst, I want to manage and investigate security incidents in Microsoft Defender for Cloud so that I can understand attack campaigns and respond effectively. ai-usage: ai-assisted ---@@ -11,7 +11,7 @@ ai-usage: ai-assisted Triaging and investigating security alerts can be time consuming for even the most skilled security analysts. For many, it's hard to know where to begin. -Defender for Cloud uses analytics to connect information between distinct security alerts. For alert details, see [Security alerts in Defender for Cloud](./alerts-overview.md) and [Manage and respond to security alerts](manage-respond-alerts.md). Using these connections, Defender for Cloud provides a single view of an attack campaign and its related alerts to help you understand attacker actions and affected resources.+Defender for Cloud uses analytics to connect information between distinct security alerts. For alert details, see [Security alerts in Defender for Cloud](./alerts-overview.md) and [Manage and respond to security alerts](manage-respond-alerts.md). Using connections between related security alerts, Defender for Cloud provides a single view of an attack campaign and its related alerts to help you understand attacker actions and affected resources. This page provides an overview of incidents in Defender for Cloud. @@ -21,6 +21,8 @@ In Defender for Cloud, a security incident is an aggregation of all alerts for a ## Manage security incidents +Perform the following steps to find and manage security incidents in Defender for Cloud:+ 1. On Defender for Cloud's security alerts page, use the **Add filter** button to filter by alert name to the alert name **Security incident detected on multiple resources**. :::image type="content" source="media/incidents/locating-incidents.png" alt-text="Locating the incidents on the security alerts page in Microsoft Defender for Cloud.":::@@ -31,29 +33,29 @@ In Defender for Cloud, a security incident is an aggregation of all alerts for a 1. To view details of an incident, select one from the list. A side pane appears with more details about the incident. - :::image type="content" source="media/incidents/incident-quick-peek.png" alt-text="Side pane showing details of the incident.":::+ :::image type="content" source="media/incidents/incident-quick-peek.png" alt-text="Screenshot of the side pane showing incident details such as severity, status, and related alerts in Microsoft Defender for Cloud."::: 1. To view more details, select **View full details**. [](media/incidents/incident-details.png#lightbox) - The left pane of the security incident page shows high-level information about the security incident: title, severity, status, activity time, description, and the affected resource. Next to the affected resource you can see the relevant Azure tags. Use these tags to infer the organizational context of the resource when investigating the alert.+ The left pane of the security incident page shows high-level information about the security incident: title, severity, status, activity time, description, and the affected resource. Next to the affected resource you can see the relevant Azure tags. Use the Azure tags shown next to the affected resource to infer the organizational context of the resource when investigating the alert. The right pane includes the **Alerts** tab with the security alerts that were correlated as part of this incident. >[!TIP] > For more information about a specific alert, select it. - [](media/incidents/incident-take-action-tab.png#lightbox)+ [](media/incidents/incident-take-action-tab.png#lightbox) - To switch to the **Take action** tab, select the tab or the button on the bottom of the right pane. Use this tab to take further actions such as:+ To switch to the **Take action** tab, select the tab or select the **Take action** button at the bottom of the right pane. Use this tab to take further actions such as: - *Mitigate the threat* - provides manual remediation steps for this security incident - *Prevent future attacks* - provides security recommendations to help reduce the attack surface, increase security posture, and prevent future attacks - *Trigger automated response* - provides the option to trigger a Logic App as a response to this security incident - *Suppress similar alerts* - provides the option to suppress future alerts with similar characteristics if the alert isn’t relevant for your organization > [!NOTE]- > The same alert can exist as part of an incident, as well as to be visible as a standalone alert.+ > A security alert can appear both as part of an incident and as a standalone alert. 1. To remediate the threats in the incident, follow the remediation steps provided with each alert. @@ -61,7 +63,8 @@ In Defender for Cloud, a security incident is an aggregation of all alerts for a - [Security alerts in Defender for Cloud](alerts-overview.md) -## Next step+<a name="next-step"></a>+## Next steps > [!div class="nextstepaction"] > [Manage and respond to security alerts](manage-respond-alerts.md) 
