Plan an incident response workflow in the Microsoft Defender portal
In brief
Updated punctuation, list formatting, wording, role-based guidance formatting, and the link text for alert correlation and incident merging documentation.
What Defender admins need to know
Administrators and responders get clearer, more consistent incident response guidance and navigation.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Plan an incident response workflow in the Microsoft Defender portal
In the Microsoft Defender portal, you can respond to security incidents that are collections of related alerts and tell the full story of an attack.
This article provides a set of steps that you can follow to investigate, analyze, and resolve security incidents in the Microsoft Defender portal, and also maps these steps to your security team's experience level and role.
| Stage | Steps |
|---|---|
| For each incident, begin an attack and alert investigation and analysis. | - View the attack story of the incident to understand its scope, severity, detection source, and which asset entities are affected. - Begin analyzing the alerts to understand their origin, scope, and severity with the alert story within the incident. - As needed, gather information on impacted devices, users, and mailboxes with the graph. Select any entity to open a flyout with all the details. Follow through to the entity page for more insights. - See how Microsoft Defender XDR has resolved alerts through automatic investigation and remediation with the Investigations tab. - As needed, use information in the data set for the incident for more information with the Evidence and Response tab. |
| After or during your analysis, perform containment to reduce any additional impact of the attack and eradication of the security threat. | For example: - Disable compromised users - Isolate impacted devices - Block hostile IP |
| As much as possible, recover from the attack by restoring your tenant resources to the state they were in before the incident. | For example: - Restore affected resources from - Manually restore previous |
| Resolve the incident and document your findings. | Take time for post-incident learning to: - Understand the type of the attack and its impact. - Research the attack in Threat Analytics and the security community for a security attack trend. - Recall the workflow you used to resolve the incident and update your standard workflows, processes, policies, and playbooks as needed. - Determine whether changes in your security configuration are needed and implement them. |
If you're new to security analysis, seeread the introduction to responding to your first incident for additional information and to step through an example incident.
For more information about incident response across Microsoft products, see incident response overview.
| Level | Steps |
|---|---|
| New | - See the Respond to your first incident walkthrough to get a guided tour of a typical process of analysis, remediation, and post-incident review in the Microsoft Defender portal with an example attack. - See which incidents should be prioritized in the incident queue based on severity and other factors. - Manage incidents, which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. |
| Experienced | - See which incidents should be prioritized in the incident queue based on severity and other factors. - Manage incidents, which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. - Investigate incidents. - Track and respond to emerging threats with threat analytics. - Proactively hunt for threats with advanced threat hunting. - See the incident response playbooks for detailed guidance for phishing, password spray, and app consent grant attacks. |
Define tasks by security team role
| Role | Steps |
|---|---|
| Incident responder (Tier 1) | Get started with the incident queue from the Incidents page of the Microsoft Defender portal. From the Incidents page, you can: - See which incidents should be prioritized in the incident queue based on severity and other factors. - Manage incidents, which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. |
| Security investigator or analyst (Tier 2) | - Perform investigations of incidents from the Incidents page of the Microsoft Defender portal. - See the incident response playbooks for detailed guidance for phishing, password spray, and app consent grant attacks. |
| Advanced security analyst or threat hunter (Tier 3) | - Perform investigations of incidents from the Incidents page of the Microsoft Defender portal. - Track and respond to emerging threats with threat analytics. - Proactively hunt for threats with advanced threat hunting. - See the incident response playbooks for detailed guidance for phishing, password spray, and app consent grant attacks. |
| SOC manager | See how to integrate Microsoft Defender XDR into your Security Operations Center (SOC). |
Related content
To learn more about alert correlation and incident merging in the Defender portal, see Alert correlation and incident merging in the Microsoft Defender portal.
@@ -19,7 +19,7 @@ ai-usage: ai-assisted # Plan an incident response workflow in the Microsoft Defender portal -In the Microsoft Defender portal, you can respond to security incidents that are collections of related alerts and tell the full story of an attack. +In the Microsoft Defender portal, you can respond to security incidents that are collections of related alerts and tell the full story of an attack. This article provides a set of steps that you can follow to investigate, analyze, and resolve security incidents in the Microsoft Defender portal, and also maps these steps to your security team's experience level and role. @@ -41,11 +41,11 @@ Consider the following incident response workflow stages and actions for your ow | Stage | Steps | | ----- | ----- | | For each incident, begin an [attack and alert investigation and analysis](/defender-xdr/investigate-incidents). | - View the attack story of the incident to understand its scope, severity, detection source, and which asset entities are affected.<br>- Begin analyzing the alerts to understand their origin, scope, and severity with the alert story within the incident.<br>- As needed, gather information on impacted devices, users, and mailboxes with the graph. Select any entity to open a flyout with all the details. Follow through to the entity page for more insights.<br>- See how Microsoft Defender XDR has resolved alerts through [automatic investigation and remediation](/defender-xdr/m365d-autoir) with the **Investigations** tab.<br>- As needed, use information in the data set for the incident for more information with the **Evidence and Response** tab. |-| After or during your analysis, perform containment to reduce any additional impact of the attack and eradication of the security threat. | For example:<br>- Disable compromised users<br>- Isolate impacted devices<br>- Block hostile IP addresses. |-| As much as possible, recover from the attack by restoring your tenant resources to the state they were in before the incident.| For example: <br>- Restore affected resources from backups.<br>- Manually restore previous configurations. |+| After or during your analysis, perform containment to reduce any additional impact of the attack and eradication of the security threat. | For example:<br>- Disable compromised users<br>- Isolate impacted devices<br>- Block hostile IP addresses |+| As much as possible, recover from the attack by restoring your tenant resources to the state they were in before the incident.| For example: <br>- Restore affected resources from backups<br>- Manually restore previous configurations | | [Resolve the incident](/defender-xdr/manage-incidents#resolve-an-incident) and document your findings. | Take time for post-incident learning to:<br>- Understand the type of the attack and its impact.<br>- Research the attack in [Threat Analytics](/defender-xdr/threat-analytics) and the security community for a security attack trend.<br>- Recall the workflow you used to resolve the incident and update your standard workflows, processes, policies, and playbooks as needed.<br>- Determine whether changes in your security configuration are needed and implement them. | -If you're new to security analysis, see the [introduction to responding to your first incident](/defender-xdr/incidents-overview) for additional information and to step through an example incident.+If you're new to security analysis, read the [introduction to responding to your first incident](/defender-xdr/incidents-overview) for additional information and to step through an example incident. For more information about incident response across Microsoft products, see [incident response overview](/security/operations/incident-response-overview). @@ -61,7 +61,7 @@ Use the following experience-level guidance for security analysis and incident r | Level | Steps | |:-------|:-----| | **New** | - See the [Respond to your first incident walkthrough](/defender-xdr/respond-first-incident-365-defender) to get a guided tour of a typical process of analysis, remediation, and post-incident review in the Microsoft Defender portal with an example attack. <br>- See which incidents should be [prioritized in the incident queue](/defender-xdr/incident-queue) based on severity and other factors.<br>- [Manage incidents](/defender-xdr/manage-incidents), which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. |-| **Experienced** | - Get started with the incident queue from the **Incidents** page of the Microsoft Defender portal. From the **Incidents** page, you can: <br>- See which incidents should be [prioritized in the incident queue](/defender-xdr/incident-queue) based on severity and other factors. <br>- [Manage incidents](/defender-xdr/manage-incidents), which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. <br>- [Investigate incidents](/defender-xdr/investigate-incidents). <br>- Track and respond to emerging threats with [threat analytics](/defender-xdr/threat-analytics). <br>- Proactively hunt for threats with [advanced threat hunting](/defender-xdr/advanced-hunting-overview). <br>- See the [incident response playbooks](/security/operations/incident-response-playbooks) for detailed guidance for phishing, password spray, and app consent grant attacks. |+| **Experienced** | Get started with the incident queue from the **Incidents** page of the Microsoft Defender portal. From the **Incidents** page, you can: <br>- See which incidents should be [prioritized in the incident queue](/defender-xdr/incident-queue) based on severity and other factors. <br>- [Manage incidents](/defender-xdr/manage-incidents), which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. <br>- [Investigate incidents](/defender-xdr/investigate-incidents). <br>- Track and respond to emerging threats with [threat analytics](/defender-xdr/threat-analytics). <br>- Proactively hunt for threats with [advanced threat hunting](/defender-xdr/advanced-hunting-overview). <br>- See the [incident response playbooks](/security/operations/incident-response-playbooks) for detailed guidance for phishing, password spray, and app consent grant attacks. | <a name="security-team-role"></a> ### Define tasks by security team role@@ -70,7 +70,7 @@ Use the following role-based guidance for your security team. | Role | Steps | |---|---|-| Incident responder (Tier 1) | Get started with the incident queue from the **Incidents** page of the Microsoft Defender portal. From the **Incidents** page, you can: - See which incidents should be [prioritized in the incident queue](/defender-xdr/incident-queue) based on severity and other factors. <br>- [Manage incidents](/defender-xdr/manage-incidents), which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. |+| Incident responder (Tier 1) | Get started with the incident queue from the **Incidents** page of the Microsoft Defender portal. From the **Incidents** page, you can: <br>- See which incidents should be [prioritized in the incident queue](/defender-xdr/incident-queue) based on severity and other factors. <br>- [Manage incidents](/defender-xdr/manage-incidents), which includes renaming, assigning, classifying, and adding tags and comments based on your incident management workflow. | | Security investigator or analyst (Tier 2) | - Perform [investigations](/defender-xdr/investigate-incidents) of incidents from the **Incidents** page of the Microsoft Defender portal.<br>- See the [incident response playbooks](/security/operations/incident-response-playbooks) for detailed guidance for phishing, password spray, and app consent grant attacks. | | Advanced security analyst or threat hunter (Tier 3) | - Perform [investigations](/defender-xdr/investigate-incidents) of incidents from the **Incidents** page of the Microsoft Defender portal. <br>- Track and respond to emerging threats with [threat analytics](/defender-xdr/threat-analytics). <br>- Proactively hunt for threats with [advanced threat hunting](/defender-xdr/advanced-hunting-overview). <br>- See the [incident response playbooks](/security/operations/incident-response-playbooks) for detailed guidance for phishing, password spray, and app consent grant attacks. | | SOC manager | See how to [integrate Microsoft Defender XDR into your Security Operations Center (SOC)](/defender-xdr/integrate-microsoft-365-defender-secops). |@@ -78,4 +78,4 @@ Use the following role-based guidance for your security team. <a name="related-items"></a> ## Related content -To learn more about alert correlation and incident merging in the Defender portal, see [Alerts, incidents, and correlation in Microsoft Defender XDR](/defender-xdr/alerts-incidents-correlation).+[Alert correlation and incident merging in the Microsoft Defender portal](/defender-xdr/alerts-incidents-correlation). 