Microsoft Defender XDR
Incidents and response

Move alerts from one incident to another in the Microsoft Defender portal

In brief

The article adds a permissions prerequisite, clarifies how to open the move panel and select alerts, and updates wording around feedback and saved moves.

What Defender admins need to know

Administrators can use the clarified guidance to verify access and follow the alert-moving procedure.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Move alerts from one incident to another in the Microsoft Defender portal

Prerequisites

Before you move alerts between incidents, make sure you have the following permissions:

  • Users must have permissions to view the incidents queue.
  • Users must have read and write permissions on all the alerts they wish to move between incidents.

Access the panel to move alerts

There are many ways to getopen the Move alerts to thisanother incident panel. You can access it from anywhere you can select or take action on alerts. For example:

In any of the following locations, select one or more alerts by marking the checkboxes at the beginning of their rows. When one or more alerts are marked, the Move alerts to another incident button appears on the toolbar.

Select the alert or alerts to move

To choose the alerts you want to move and open the move panel, follow these steps:

  1. Open the Incidents queue, the Alerts tab on the incident details page, the Alerts queue, or an alert details page.

  2. Select the alert or alerts you want to move by marking the checkboxes at the beginning of their rows in the queue. When one or more alerts are marked, the Move alerts to another incident button appears on the toolbar.

    :::image type="content" source="media/move-alert-to-another-incident/move-alert-to-another-incident-from-alerts-tab.png" alt-text="Screenshot of selecting alerts from the queue to move to another incident." lightbox="media/move-alert-to-another-incident/move-alert-to-another-incident-from-alerts-tab.png":::

  3. Select Move alerts to another incident from the toolbar. A flyout panel opens. If you selected only one alert, the panel is labeled Move alert to another incident. If you selected two or more alerts, it's labeled Move multiple alerts to another incident. In all other respects, it's the same panel.flyout panel is the same.

  4. If the alert or alerts belong with another existing incident, select Link to an existing incident. Otherwise, select Create a new incident. Alerts must belong to an incident.

    :::image type="content" source="media/move-alert-to-another-incident/move-alert-to-existing-incident-save.png" alt-text="Screenshot of adding a comment explaining why moving an alert.":::

  5. Provide feedback explaining why you are moving the alert or alerts by selecting one of the predefined options. This stepProviding feedback helps Microsoft improve alert correlation in the future.

  6. Select Save at the bottom of the panel to execute the move.

  7. If you selected Create a new incident, enter a comment explaining why you want to move the alerts.

  8. Provide feedback explaining why you are moving the alert or alerts by selecting one of the predefined options. This stepProviding feedback helps Microsoft improve alert correlation in the future.

  9. Select Save at the bottom of the panel to execute the move.

    :::image type="content" source="media/move-alert-to-another-incident/move-alert-to-new-incident.png" alt-text="Screenshot of selecting a new incident to move an alert to.":::

    WhenAfter the processmove is completed,saved, a new incident is created with the alert or alerts you moved to it. The incident is given a name automatically based on the name of the alert or alerts.

Review activity log entries for moved alerts