[Index]

Model: device/msgraphsecurity/Incident

Incidents

Full HTML Help

MICROSOFT

Overview

Automate provides support for Microsoft Defender for Endpoint, that addresses user devices (laptops, phones, tablets, PCs) and network devices (access points, routers, firewalls).

Note

Dashboards

The administrator interface provides dashboards for the view and management of data:

Dashboards:
Security Management - Defender for Endpoint Overview Security Management - Defender for Endpoint Actions
Dashboards:

To customize your dashboards:

Incident and Alert Actions

Incidents

Related device model: device/msgraphsecurity/Incident

Automate provides an Incidents list view showing such headings as the incident Status and Severity at a hierarchy (Located At), and allows for the examination of the Details of an incident, including for example the Incident Web URL at security.microsoft.com.

Alerts

Related device model: device/msgraphsecurity/Alerts

Automate provides an Alerts list view showing such headings as the incident Title, Status, Severity, Description and Device at a hierarchy (Located At), and allows for the Details of an instance to be viewed and managed.

Managing an alert

Administrators can manage the following alert properties:

Device Actions

View Devices

Related device model: device/mssecurity/Machine

Automate provides an View Devices list view showing such headings as the Last IP Address, Health Status, Exposure Level and Device at a hierarchy (Located At), and allows for the examination of the Details of a device.

Bulk Actions

Automate provides an interface to carry out bulk actions on devices. For Target Defender Devices, the Available and Selected transfer boxes are available to select devices accessible from a hierarchy to carry out operations in bulk:

Machine Action

The relation/MachineAction model is available to allow for the execution of Cancel action. (This action sends a request to device/mssecurity/MachineActionCancel.)

Related Topics

Model Details: device/msgraphsecurity/Incident

Title Description Details
Id
  • Field Name: id
  • Type: String
Tenant ID
  • Field Name: tenantId
  • Type: String
Status
  • Field Name: status
  • Type: String
Incident Web URL
  • Field Name: incidentWebUrl
  • Type: String
Redirect Incident ID
  • Field Name: redirectIncidentId
  • Type: String
Display Name
  • Field Name: displayName
  • Type: String
Created DateTime
  • Field Name: createdDateTime
  • Type: String
  • Format: date-time
Last Update DateTime
  • Field Name: lastUpdateDateTime
  • Type: String
  • Format: date-time
Assigned To
  • Field Name: assignedTo
  • Type: String
Classification
  • Field Name: classification
  • Type: String
Determination
  • Field Name: determination
  • Type: String
Severity
  • Field Name: severity
  • Type: String
Custom Tags
  • Field Name: customTags.[n]
  • Type: Array
System Tags
  • Field Name: systemTags.[n]
  • Type: Array
Description
  • Field Name: description
  • Type: String
Last Modified By
  • Field Name: lastModifiedBy
  • Type: String
Resolving Comment
  • Field Name: resolvingComment
  • Type: String
Summary
  • Field Name: summary
  • Type: String
Comments
  • Field Name: comments.[n]
  • Type: Array