What are incidents in Microsoft 365 Defender?

Experience Level: Junior
Tags: Microsoft Defender

Answer

An incident in Microsoft 365 Defender is a collection of correlated alerts and associated data that make up the story of an attack.

Microsoft 365 services and apps create alerts when they detect a suspicious or malicious event or activity. Individual alerts provide valuable clues about a completed or ongoing attack. However, attacks typically employ various techniques against different types of entities, such as devices, users, and mailboxes. The result is multiple alerts for multiple entities in your tenant.

Because piecing the individual alerts together to gain insight into an attack can be challenging and time-consuming, Microsoft 365 Defender automatically aggregates the alerts and their associated information into an incident.
Azure - Compliance for beginners
Azure - Compliance for beginners

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself
Azure - Security for beginners
Azure - Security for beginners

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself
SC-900: Microsoft Security, Compliance, and Identity Fundamentals preparation
SC-900: Microsoft Security, Compliance, and Identity Fundamentals preparation

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself