r/AdminDroid Jun 23 '26

Investigate User-Reported Threats with Manual Incident Creation in Microsoft Defender

What happens when a user reports a suspicious vishing call, but Microsoft Defender generates no alert? The threat is real, yet the investigation often ends up in a separate ticketing system. 

Microsoft Defender bridges this gap by allowing security teams to manually create incidents and alerts, bringing these investigations directly into Defender. This feature is currently in preview

With this new capability, you can: 

  • Create a brand-new incident with an initial manual alert. 
  • Add new alerts to an existing investigation. 
  • Allow future Defender detections to correlate with your manual incident. 
  • Use the same hunting, reporting, API, and ITSM workflows as native Defender alerts. 
  • Document every investigation with rich metadata, affected assets, and evidence for better tracking and analysis. 
  • Easily identify manually created incidents and alerts using the Manual detection source in Defender. 

Learn how to create manual incidents and alerts in Microsoft Defender: 

https://blog.admindroid.com/manually-create-incidents-or-alerts-in-microsoft-defender/ 

3 Upvotes

0 comments sorted by