Incident investigations in Microsoft Defender ATP

Created by Shekhar Rathour, Modified on Thu, 13 Aug, 2020 at 9:05 PM by Shekhar Rathour

The Incidents queue is the starting point for threat investigations. It provides high-level information about each incident, like the impacted machines, the sources of alerts, and the severity. Incidents optimize your time by helping you to triage, investigate, and remediate related alerts together. For more tips like this, check out the working remotely playlist at www.youtube.com/FoetronAcademy . Also, if you need any further assistance then you can raise a support ticket and get it addressed.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article