Skip to content

Commit f671f79

Browse files
Merge pull request #3654 from yelevin/patch-1
Added rich text support
2 parents 7ca2038 + 5009457 commit f671f79

File tree

1 file changed

+10
-10
lines changed

1 file changed

+10
-10
lines changed

unified-secops-platform/cases-overview.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,25 @@
11
---
2-
title: Manage cases natively in Microsoft's unified SecOps platform
3-
description: Learn about case management features across Microsoft's unified security operations (SecOps) platform.
2+
title: Manage cases natively in the Microsoft Defender portal
3+
description: Learn about case management features for unified security operations in the Defender portal.
44
search.appverid: met150
55
ms.service: unified-secops-platform
6-
ms.author: austinmc
7-
author: austinmccollum
6+
ms.author: yelevin
7+
author: yelevin
88
ms.localizationpriority: medium
9-
ms.date: 01/16/2025
9+
ms.date: 05/04/2025
1010
audience: ITPro
1111
ms.collection:
1212
- M365-security-compliance
1313
- tier1
1414
- usx-security
1515
ms.topic: conceptual
1616

17-
# customer intent: As a security operations center business decision maker, I want to learn about the case management tool available in Microsoft's unified SecOps platform so I can unify security tickets and case management tools so I can get visibility into, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments.
17+
# customer intent: As a security operations center business decision maker, I want to learn about the case management tools available in the Microsoft Defender portal so I can unify security tickets, increase visibility, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments.
1818
---
1919

20-
# Manage cases natively in Microsoft's unified security operations platform
20+
# Manage cases natively in the Microsoft Defender portal
2121

22-
Case management is the first installment of new capabilities for managing security work when you onboard to Microsoft's unified security operations (SecOps) platform.
22+
Case management is the first installment of new unified security operations (SecOps) capabilities for managing security work in the Microsoft Defender portal.
2323

2424
This initial step toward delivering a unified, security-focused case management experience centralizes rich collaboration, customization, evidence collection, and reporting across SecOps workloads. SecOps teams maintain security context, work more efficiently, and respond faster to attacks when they manage case work without leaving the Defender portal.
2525

@@ -81,7 +81,7 @@ Manage the following case details to describe, prioritize, assign, and track wor
8181
| Priority| `Very low`, `Low`, `Medium`, `High`, `Critical` | none |
8282
| Status | Set by analysts, customizable by admins | Default statuses are `New`, `Open`, and `Closed`</br>Default value is `New`|
8383
| Assigned to | A single user in the tenant | none |
84-
| Description | Plain text | none |
84+
| Description | Rich text | none |
8585
| Case details | Case ID | Case IDs start at 1000 and aren't purged. Use custom statuses and filters to archive cases. Case numbers are automatically set.|
8686
| | Created by</br>Created on</br>Last updated by</br>Last updated on | automatically set |
8787
| | Due on</br>Linked incidents | none |
@@ -117,7 +117,7 @@ Each case has a threshold of 100 linked incidents.
117117

118118
### Activity log
119119

120-
Need to write down notes, or that key detection logic to pass along? Create plain text comments and review the audit events in the activity log. Comments are a great place to quickly add information to a case.
120+
Need to write down notes, or that key detection logic to pass along? Create rich text comments and review the audit events in the activity log. Comments are a great place to quickly add information&mdash;including such things as queries, tables, links, and structured content&mdash;to a case.
121121

122122
:::image type="content" source="media/cases-overview/informal-comments.png" alt-text="Screenshot showing informal comments between analysts.":::
123123

0 commit comments

Comments
 (0)