Microsoft Unified SecOps Platform
General

View and manage incidents and alerts in Microsoft Defender multitenant management

In brief

The article now more clearly explains viewing and managing incidents and alerts across tenants. Status changes, classification, tagging, and comments can span tenants, while assigning multiple incidents or alerts is limited to items from the same tenant.

What Defender admins need to know

No configuration change is required. Administrators should use the tenant-specific portal for detailed incident or alert actions and account for the same-tenant assignment limit.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

View and manage incidents and alerts in Microsoft Defender multitenant management

Multi-tenantMultitenant management forin the Defender portal brings together data from multiple tenants and Microsoft Sentinel workspaces in one place. Security operations center (SOC) analysts can use it to quickly find and respond to threats across Microsoft Defender XDR and Microsoft Sentinel. You can triage incidents and alerts that span SIEM and XDR data for any tenant with a Microsoft Sentinel inworkspace onboarded to the Defender portal enables security operation center (SOC) analystsplatform.

This article shows you how to accessview, investigate, and analyze datamanage incidents and alerts from multiple tenants and workspaces in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data for tenants that onboarded a Microsoft Sentinel workspace toby using the Defender platform.

Manage incidents & alerts originating from multiple tenants and workspaces under Incidents & alerts. pages.

View and investigate incidents

  1. Select the incident you want to view. A flyout opens with the incident details pane, where you can:

    • Select Open incident page to view thisopen the incident in a new tab for the specificthat tenant in the Microsoft Defender portal.
    • Select Manage incident to assignassign, tag, classify, or change the incident, set incident tags, set the incident status, and classifystatus of the incident.

To learn more, see Investigate incidents.

Manage multiple incidents

To manage incidents across multiple tenants and workspaces:

  1. Go to the Incidents page

    To manage incidents across multiple tenants and workspaces:

    1. Go to the Incidents page in Microsoft Defender multitenant management.

      :::image type="content" source="media/mto-incidents-alerts/mto-manage-incidents.png" alt-text="Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-incidents.png":::

    On the incidents flyout panepane, you can assign incidents, assignassign, tag, classify, or change the status of incidents tags, set the incident status, and classify multiple incidents foracross multiple tenants simultaneously.at once.

    To learn more about incidents in the Microsoft Defender portal, see Manage incidents

    To learn more about incidents in the Microsoft Defender portal, see Manage incidents.

    1. From the alert details pane you can:

      • Select actions such as Open alerts page, Move alert to another incident, andor Tune alert to view thisopen the alert in a new tab for the specificthat tenant in the Microsoft Defender portal.
      • Select Manage alert to assignassign, classify, or change the alert, set the alert status, and classifystatus of the alert.

    To learn more, see Investigate alerts.

    :::image type="content" source="media/mto-incidents-alerts/mto-manage-alerts.png" alt-text="Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-alerts.png":::

    Use the Manage alerts pane to set alertthe status, assign alerts, set classifications,assign, classify, and add comments for multiple alerts simultaneously. While alertat once. You can set status, classifications, and comments can be added across tenants, assigning alertstenants. However, you can only be done forassign alerts from the same tenant.

    For more information, see Manage alerts.