Manually Create Incident
In brief
The article now clarifies the Related incident step, adds navigation support, updates the date and metadata, and provides additional incident-management references.
What Defender admins need to know
Administrators can more easily follow and navigate the manual alert and incident creation process. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Manual incident and alert creation lets your security operations center (SOC) team create incidents and alerts as needed in the Microsoft Defender portal. Use it to track investigations, tips from other teams, or operational work in the unified incident queue, even if no automatic detection has triggered.
This article describes how to manually create an incident or alert from the Defender portal. After you create an incident, manage the incident like any other incident in the queue.
What you can do with manual creation
Manual creation supports the following capabilities:
- Create a new incident with an initial alert, or attach an alert to an existing incident.
- Provide full incident metadata, including title, description, severity, category, MITRE ATT&CK techniques, impacted assets, and evidence.
- Decide whether the incident participates in correlation, or keep it standalone.
Select Next to continue.
Step 5: RelatedLink the alert to a related incident
Select if you wantOn the Related incident step, select whether to create a new incident or correlate the alert with an existing incident. If you choose to correlate with an existing incident, provide the incident ID.
:::image type="content" source="./media/manually-create-incident/related-incident.png" alt-text="Screenshot of the Related incident step of the Create new wizard, showing the option to correlate with an existing incident and the incident ID input field." lightbox="./media/manually-create-incident/related-incident.png":::
Related articles
For more information about incident management and related tasks, see the following articles:
@@ -13,10 +13,11 @@ ms.collection: - tier1 ms.topic: how-to ai-usage: ai-assisted-ms.date: 06/03/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal+ms.custom: msecd-doc-authoring-1016 #customer intent: As a security operations analyst, I want to manually create an incident or alert in the Microsoft Defender portal so that I can capture observations, drive investigations, and integrate with my ITSM workflows on demand. ---@@ -30,10 +31,12 @@ appliesto: Manual incident and alert creation lets your security operations center (SOC) team create incidents and alerts as needed in the [Microsoft Defender portal](https://security.microsoft.com). Use it to track investigations, tips from other teams, or operational work in the unified incident queue, even if no automatic detection has triggered. -This article describes how to manually create an incident or alert from the Defender portal. After you create an incident, [manage it](manage-incidents.md) like any other incident in the queue.+This article describes how to manually create an incident or alert from the Defender portal. After you create an incident, [manage the incident](manage-incidents.md) like any other incident in the queue. ## What you can do with manual creation +Manual creation supports the following capabilities:+ - Create a new incident with an initial alert, or attach an alert to an existing incident. - Provide full incident metadata, including title, description, severity, category, MITRE ATT&CK techniques, impacted assets, and evidence. - Decide whether the incident participates in correlation, or keep it standalone.@@ -108,9 +111,10 @@ You can only add assets that are within your RBAC scope. Select **Next** to continue. -### Step 5: Related incident+<a name="step-5-related-incident"></a>+### Step 5: Link the alert to a related incident -Select if you want to create a new incident or correlate the alert with an existing incident. If you choose to correlate with an existing incident, provide the incident ID.+On the **Related incident** step, select whether to create a new incident or correlate the alert with an existing incident. If you choose to correlate with an existing incident, provide the incident ID. :::image type="content" source="./media/manually-create-incident/related-incident.png" alt-text="Screenshot of the Related incident step of the Create new wizard, showing the option to correlate with an existing incident and the incident ID input field." lightbox="./media/manually-create-incident/related-incident.png"::: @@ -137,6 +141,8 @@ All create and update actions on a manually generated incident appear in the inc ## Related articles +For more information about incident management and related tasks, see the following articles:+ - [Manage incidents in Microsoft Defender](manage-incidents.md) - [Move alerts to another incident](move-alert-to-another-incident.md) - [Merge incidents manually](merge-incidents-manually.md) 