Skip to content

Commit 649904b

Browse files
Merge pull request #3350 from batamig/adding-alert-actions
fixing alert docs for MTO
2 parents 2720224 + 1ac366a commit 649904b

File tree

3 files changed

+25
-16
lines changed

3 files changed

+25
-16
lines changed
179 KB
Loading
125 KB
Loading

unified-secops-platform/mto-incidents-alerts.md

Lines changed: 25 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -30,20 +30,16 @@ Multiple workspaces per tenant are supported in multitenant management as previe
3030

3131
## View and investigate incidents
3232

33-
To view or investigate an incident:
33+
To view or investigate an incident:
3434

3535
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management. The **Tenant name** and **Workspaces** columns show which tenant the incident originates from:
3636

3737
:::image type="content" source="media/mto-incidents-alerts/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents page." lightbox="media/mto-incidents-alerts/mto-incidents.png":::
3838

39-
2. Select the incident you want to view. A flyout panel opens with the incident details page:
39+
1. Select the incident you want to view. A flyout opens with the incident details pane, where you can:
4040

41-
:::image type="content" source="media/mto-incidents-alerts/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents details page." lightbox="media/mto-incidents-alerts/mto-incident-details.png":::
42-
43-
3. From the incident details page you can:
44-
45-
- Select **Open incident page** to view this incident in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
46-
- Select **Manage incident** to assign the incident, set incident tags, set the incident status, and classify the incident.
41+
- Select **Open incident page** to view this incident in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
42+
- Select **Manage incident** to assign the incident, set incident tags, set the incident status, and classify the incident.
4743

4844
To learn more, see [Investigate incidents](/defender-endpoint/investigate-incidents).
4945

@@ -56,7 +52,10 @@ To manage incidents across multiple tenants and workspaces:
5652

5753
:::image type="content" source="media/mto-incidents-alerts/mto-manage-incidents.png" alt-text="Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-incidents.png":::
5854

59-
On the incidents fly-out you can set severity, assign incident tags, assign incidents, set the incident status, and classify multiple incidents for multiple tenants and workspaces simultaneously.
55+
On the incidents flyout pane you can assign incidents, assign incidents tags, set the incident status, and classify multiple incidents for multiple tenants simultaneously.
56+
57+
>[!Note]
58+
> Currently, you can only assign multiple incidents from same tenant.
6059
6160
To learn more about incidents in the Microsoft Defender portal, see [Manage incidents](/defender-endpoint/manage-incidents).
6261

@@ -68,10 +67,10 @@ To view or investigate an alert:
6867

6968
:::image type="content" source="media/mto-incidents-alerts/mto-alerts-details.png" alt-text="Screenshot of alert details page for an alert in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-alerts-details.png":::
7069

71-
2. From the alert details page you can:
70+
1. From the alert details pane you can:
7271

73-
- Select actions such as **Open alerts page**, **See in timeline**, and **Tune alert** to view this alert in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
74-
- Select **Manage alert** to assign the alert, set the alert status, and classify the alert.
72+
- Select actions such as **Open alerts page**, **Move alert to another incident**, and **Tune alert** to view this alert in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com).
73+
- Select **Manage alert** to assign the alert, set the alert status, and classify the alert.
7574

7675
To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
7776

@@ -80,14 +79,24 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
8079
To manage alerts across multiple tenants and workspaces:
8180

8281
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in Microsoft Defender multitenant management.
83-
84-
1. Select the alerts you want to manage from the alerts list, and then select **Manage alerts**.
82+
1. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
8583

8684
:::image type="content" source="media/mto-incidents-alerts/mto-manage-alerts.png" alt-text="Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management." lightbox="media/mto-incidents-alerts/mto-manage-alerts.png":::
8785

88-
1. Select any specific alert to view the alert fly-out, where you can assign alerts, set the alert status, and classify the alerts for multiple tenants and workspaces.
86+
Use the **Manage alerts** pane to set alert status, assign alerts, set classifications, and add comments for multiple alerts simultaneously. While alert status, classifications, and comments can be added across tenants, assigning alerts can only be done for alerts from the same tenant.
87+
88+
For more information, see [Manage alerts](/defender-xdr/investigate-alerts#manage-alerts).
89+
90+
## Move alerts
91+
92+
Move an alert to a different incident to help you better organize and correlate related security events. For example, you might find that multiple alerts are part of the same security breach, and want to include them all in the same incident. This ensures that all relevant information is grouped together, enabling more efficient investigation and response.
93+
94+
To move one or more alerts:
95+
96+
- On the **Alerts** page, select one or more alerts and then select **Move alerts**
97+
- On an alert details pane or alert details page, select **Move alert to another incident**
8998

90-
For more information, see [Manage alerts](/defender-endpoint/manage-alerts).
99+
In the **Move alert to another incident** pane, define whether you want to create a new incident, or use an existing incident. If you choose to use an existing incident, search for the incident by name or ID and add a reason for the change. In all cases, add a comment describing your change before you select **Save**.
91100

92101
## Related content
93102

0 commit comments

Comments
 (0)