Edit

View and manage incidents and alerts in Microsoft Defender multitenant management

Multitenant management in the Defender portal brings together data from multiple tenants and Microsoft Sentinel workspaces in one place. Security operations center (SOC) analysts can use it to quickly find and respond to threats across Microsoft Defender XDR and Microsoft Sentinel. You can triage incidents and alerts that span SIEM and XDR data for any tenant with a Microsoft Sentinel workspace onboarded to the Defender platform.

This article shows you how to view, investigate, and manage incidents and alerts from multiple tenants and workspaces by using the Incidents & alerts pages.

View and investigate incidents

To view or investigate an incident:

  1. Go to the Incidents page in Microsoft Defender multitenant management. The Tenant name and Workspaces columns show which tenant the incident originates from:

    Screenshot of the Microsoft Defender multitenant incidents page.

  2. Select the incident you want to view. A flyout opens with the incident details pane, where you can:

    • Select Open incident page to open the incident in a new tab for that tenant in the Microsoft Defender portal.
    • Select Manage incident to assign, tag, classify, or change the status of the incident.

To learn more, see Investigate incidents.

Manage multiple incidents

Note

Currently, you can only assign multiple incidents from same tenant.

To manage incidents across multiple tenants and workspaces:

  1. Go to the Incidents page in Microsoft Defender multitenant management.

  2. Choose the incidents you want to manage from the incidents list and select Manage incidents.

    Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management.

On the flyout pane, you can assign, tag, classify, or change the status of incidents across multiple tenants at once.

To learn more about incidents in the Microsoft Defender portal, see Manage incidents.

View and investigate alerts

To view or investigate an alert:

  1. Go to the Alerts page in multitenant management and select the alert you want to view. A flyout panel opens with the alert details page:

    Screenshot of alert details page for an alert in Microsoft Defender multitenant management.

  2. From the alert details pane you can:

    • Select Open alerts page, Move alert to another incident, or Tune alert to open the alert in a new tab for that tenant in the Microsoft Defender portal.
    • Select Manage alert to assign, classify, or change the status of the alert.

To learn more, see Investigate alerts.

Manage multiple alerts

To manage alerts across multiple tenants and workspaces:

  1. Go to the Alerts page in Microsoft Defender multitenant management.

  2. Choose the alerts you want to manage from the alerts list and select Manage alerts.

    Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management.

Use the Manage alerts pane to set the status, assign, classify, and add comments for multiple alerts at once. You can set status, classifications, and comments across tenants. However, you can only assign alerts from the same tenant.

For more information, see Manage alerts.

Move alerts

Move an alert to a different incident to help you better organize and correlate related security events. For example, you might find that multiple alerts are part of the same security breach, and want to include them all in the same incident. Grouping related alerts into the same incident ensures that all relevant information is grouped together, enabling more efficient investigation and response.

To move one or more alerts:

  • On the Alerts page, select one or more alerts and then select Move alerts
  • On an alert details pane or alert details page, select Move alert to another incident

In the Move alert to another incident pane, define whether you want to create a new incident, or use an existing incident. If you choose to use an existing incident, search for the incident by name or ID and add a reason for the change. In all cases, add a comment describing your change before you select Save.