Microsoft Defender XDR
General

Merge Incidents Manually

In brief

The article’s metadata was updated, and the instruction about providing feedback when merging incidents was reworded to emphasize its value for improving alert correlation.

What Defender admins need to know

Administrators will see clearer wording when following the manual incident merge procedure; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Incidents are automatically created in the Microsoft Defender portal when suspicious activities are detected. When two incidents describe parts of the same attack story, Defender usually merges those incidents into a single incident automatically to help you investigate incidents more efficiently and effectively and resolve them more quickly and accurately.

Sometimes, however, automatic incident merging doesn't happen, due to certain conditions that prevent incidents from being merged. To learn more about when incidents are or aren't merged, see Incident correlation and merging. When automatic incident merging doesn't occur, or if you decide independently that two (unmerged) incidents are related and should be investigated as a single unit, you can merge them manually. This article explainsThe following sections explain how to merge incidents manually.

Prerequisites

  1. In the Reason for merging text box, type a description of the reason why you want to merge the incidents.

  2. Provide feedback explaining why you are merging the incidents by selecting one of the predefined options. This stepProviding this feedback helps Microsoft improve alert correlation in the future.

  3. Select Merge incidents at the bottom of the flyout to execute the merge.