You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: unified-secops-platform/mto-incidents-alerts.md
+25-16Lines changed: 25 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,20 +30,16 @@ Multiple workspaces per tenant are supported in multitenant management as previe
30
30
31
31
## View and investigate incidents
32
32
33
-
To view or investigate an incident:
33
+
To view or investigate an incident:
34
34
35
35
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management. The **Tenant name** and **Workspaces** columns show which tenant the incident originates from:
36
36
37
37
:::image type="content" source="media/mto-incidents-alerts/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents page." lightbox="media/mto-incidents-alerts/mto-incidents.png":::
38
38
39
-
2. Select the incident you want to view. A flyout panel opens with the incident details page:
39
+
1. Select the incident you want to view. A flyout opens with the incident details pane, where you can:
40
40
41
-
:::image type="content" source="media/mto-incidents-alerts/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents details page." lightbox="media/mto-incidents-alerts/mto-incident-details.png":::
42
-
43
-
3. From the incident details page you can:
44
-
45
-
- Select **Open incident page** to view this incident in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
46
-
- Select **Manage incident** to assign the incident, set incident tags, set the incident status, and classify the incident.
41
+
- Select **Open incident page** to view this incident in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
42
+
- Select **Manage incident** to assign the incident, set incident tags, set the incident status, and classify the incident.
47
43
48
44
To learn more, see [Investigate incidents](/defender-endpoint/investigate-incidents).
49
45
@@ -56,7 +52,10 @@ To manage incidents across multiple tenants and workspaces:
56
52
57
53
:::image type="content" source="media/mto-incidents-alerts/mto-manage-incidents.png" alt-text="Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-incidents.png":::
58
54
59
-
On the incidents fly-out you can set severity, assign incident tags, assign incidents, set the incident status, and classify multiple incidents for multiple tenants and workspaces simultaneously.
55
+
On the incidents flyout pane you can assign incidents, assign incidents tags, set the incident status, and classify multiple incidents for multiple tenants simultaneously.
56
+
57
+
>[!Note]
58
+
> Currently, you can only assign multiple incidents from same tenant.
60
59
61
60
To learn more about incidents in the Microsoft Defender portal, see [Manage incidents](/defender-endpoint/manage-incidents).
62
61
@@ -68,10 +67,10 @@ To view or investigate an alert:
68
67
69
68
:::image type="content" source="media/mto-incidents-alerts/mto-alerts-details.png" alt-text="Screenshot of alert details page for an alert in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-alerts-details.png":::
70
69
71
-
2. From the alert details page you can:
70
+
1. From the alert details pane you can:
72
71
73
-
- Select actions such as **Open alerts page**, **See in timeline**, and **Tune alert** to view this alert in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
74
-
- Select **Manage alert** to assign the alert, set the alert status, and classify the alert.
72
+
- Select actions such as **Open alerts page**, **Move alert to another incident**, and **Tune alert** to view this alert in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
73
+
- Select **Manage alert** to assign the alert, set the alert status, and classify the alert.
75
74
76
75
To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
77
76
@@ -80,14 +79,24 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
80
79
To manage alerts across multiple tenants and workspaces:
81
80
82
81
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in Microsoft Defender multitenant management.
83
-
84
-
1. Select the alerts you want to manage from the alerts list, and then select **Manage alerts**.
82
+
1. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
85
83
86
84
:::image type="content" source="media/mto-incidents-alerts/mto-manage-alerts.png" alt-text="Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-alerts.png":::
87
85
88
-
1. Select any specific alert to view the alert fly-out, where you can assign alerts, set the alert status, and classify the alerts for multiple tenants and workspaces.
86
+
Use the **Manage alerts** pane to set alert status, assign alerts, set classifications, and add comments for multiple alerts simultaneously. While alert status, classifications, and comments can be added across tenants, assigning alerts can only be done for alerts from the same tenant.
87
+
88
+
For more information, see [Manage alerts](/defender-xdr/investigate-alerts#manage-alerts).
89
+
90
+
## Move alerts
91
+
92
+
Move an alert to a different incident to help you better organize and correlate related security events. For example, you might find that multiple alerts are part of the same security breach, and want to include them all in the same incident. This ensures that all relevant information is grouped together, enabling more efficient investigation and response.
93
+
94
+
To move one or more alerts:
95
+
96
+
- On the **Alerts** page, select one or more alerts and then select **Move alerts**
97
+
- On an alert details pane or alert details page, select **Move alert to another incident**
89
98
90
-
For more information, see [Manage alerts](/defender-endpoint/manage-alerts).
99
+
In the **Move alert to another incident** pane, define whether you want to create a new incident, or use an existing incident. If you choose to use an existing incident, search for the incident by name or ID and add a reason for the change. In all cases, add a comment describing your change before you select **Save**.
0 commit comments