Microsoft Sentinel
Cloud and workloads

Multiple Workspace View

In brief

The article now states that selecting an incident and choosing **View full details** or **Investigate** switches to the selected incident’s workspace context. Documentation metadata was also updated.

What Defender admins need to know

Administrators have clearer guidance on which workspace context these actions use.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to manage and investigate incidents across multiple workspaces and tenants so that I can maintain comprehensive visibility and control over my organization's security posture.

  • You need to have read and write permissions on all the workspaces from which you've selected incidents. If you have only read permissions on some workspaces, you see warning messages if you select incidents in those workspaces. You aren't able to modify those incidents or any others you've selected together with those (even if you do have permissions for the others).

  • If you choose a single incident and select View full details or Actions > Investigate, you'll from then on be in the data context of thatthe selected incident's workspace and no others.

Related content