|
1 | 1 | ---
|
2 |
| -title: Manage cases natively in Microsoft's unified SecOps platform |
3 |
| -description: Learn about case management features across Microsoft's unified security operations (SecOps) platform. |
| 2 | +title: Manage cases natively in the Microsoft Defender portal |
| 3 | +description: Learn about case management features for unified security operations in the Defender portal. |
4 | 4 | search.appverid: met150
|
5 | 5 | ms.service: unified-secops-platform
|
6 |
| -ms.author: austinmc |
7 |
| -author: austinmccollum |
| 6 | +ms.author: yelevin |
| 7 | +author: yelevin |
8 | 8 | ms.localizationpriority: medium
|
9 |
| -ms.date: 01/16/2025 |
| 9 | +ms.date: 05/04/2025 |
10 | 10 | audience: ITPro
|
11 | 11 | ms.collection:
|
12 | 12 | - M365-security-compliance
|
13 | 13 | - tier1
|
14 | 14 | - usx-security
|
15 | 15 | ms.topic: conceptual
|
16 | 16 |
|
17 |
| -# customer intent: As a security operations center business decision maker, I want to learn about the case management tool available in Microsoft's unified SecOps platform so I can unify security tickets and case management tools so I can get visibility into, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments. |
| 17 | +# customer intent: As a security operations center business decision maker, I want to learn about the case management tools available in the Microsoft Defender portal so I can unify security tickets, increase visibility, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments. |
18 | 18 | ---
|
19 | 19 |
|
20 |
| -# Manage cases natively in Microsoft's unified security operations platform |
| 20 | +# Manage cases natively in the Microsoft Defender portal |
21 | 21 |
|
22 |
| -Case management is the first installment of new capabilities for managing security work when you onboard to Microsoft's unified security operations (SecOps) platform. |
| 22 | +Case management is the first installment of new unified security operations (SecOps) capabilities for managing security work in the Microsoft Defender portal. |
23 | 23 |
|
24 | 24 | This initial step toward delivering a unified, security-focused case management experience centralizes rich collaboration, customization, evidence collection, and reporting across SecOps workloads. SecOps teams maintain security context, work more efficiently, and respond faster to attacks when they manage case work without leaving the Defender portal.
|
25 | 25 |
|
@@ -81,7 +81,7 @@ Manage the following case details to describe, prioritize, assign, and track wor
|
81 | 81 | | Priority| `Very low`, `Low`, `Medium`, `High`, `Critical` | none |
|
82 | 82 | | Status | Set by analysts, customizable by admins | Default statuses are `New`, `Open`, and `Closed`</br>Default value is `New`|
|
83 | 83 | | Assigned to | A single user in the tenant | none |
|
84 |
| -| Description | Plain text | none | |
| 84 | +| Description | Rich text | none | |
85 | 85 | | Case details | Case ID | Case IDs start at 1000 and aren't purged. Use custom statuses and filters to archive cases. Case numbers are automatically set.|
|
86 | 86 | | | Created by</br>Created on</br>Last updated by</br>Last updated on | automatically set |
|
87 | 87 | | | Due on</br>Linked incidents | none |
|
@@ -117,7 +117,7 @@ Each case has a threshold of 100 linked incidents.
|
117 | 117 |
|
118 | 118 | ### Activity log
|
119 | 119 |
|
120 |
| -Need to write down notes, or that key detection logic to pass along? Create plain text comments and review the audit events in the activity log. Comments are a great place to quickly add information to a case. |
| 120 | +Need to write down notes, or that key detection logic to pass along? Create rich text comments and review the audit events in the activity log. Comments are a great place to quickly add information—including such things as queries, tables, links, and structured content—to a case. |
121 | 121 |
|
122 | 122 | :::image type="content" source="media/cases-overview/informal-comments.png" alt-text="Screenshot showing informal comments between analysts.":::
|
123 | 123 |
|
|
0 commit comments