Until now, incidents and alerts in Defender were primarily created through automated detections. With this new capability, SOC teams can create them on demand and track security activities that don’t originate from a Defender alert.
Some practical use cases:
✅ Document investigations triggered by external threat intelligence
✅ Track security concerns reported by users or other teams
✅ Create incidents for tabletop exercises and response testing
✅ Keep operational security work visible in the unified incident queue
Manually created incidents support rich metadata, including severity, MITRE ATT&CK techniques, impacted assets, and evidence.
They also flow through the same hunting tables, APIs, audit logs, and ITSM integrations as native Defender incidents.
Admins can choose whether a manually created incident participates in Defender’s correlation engine or remains a standalone investigation.
Currently available in preview.