|
1 | | -# Resolve open incidents on devices |
| 1 | +# Investigate Incident Details & Remediate as Necessary (Daily) |
2 | 2 |
|
3 | | -**Implementation Effort:** Medium: Customer IT and Security Operations teams need to drive projects to investigate and resolve incidents using Microsoft Defender for Endpoint. |
4 | | - |
5 | | -**User Impact:** Medium: A subset of non-privileged users, such as IT staff and security analysts, may need to take action or be notified of changes. |
| 3 | +**Implementation Effort:** Medium — Security operations teams must perform daily review and triage of incidents, which requires ongoing analyst time but no major implementation projects. |
| 4 | +**User Impact:** Low — All work happens within security teams; end users do not need to take action or be notified of changes. |
6 | 5 |
|
7 | 6 | ## Overview |
8 | | -Microsoft Defender for Endpoint provides tools to investigate incidents affecting your network, understand their implications, and collate evidence to resolve them. This capability is crucial for maintaining a Zero Trust framework by ensuring that all incidents are thoroughly analyzed and remediated to prevent security breaches. |
| 7 | +Daily investigation of incidents in Microsoft Defender for Endpoint gives security analysts a complete understanding of ongoing threats by correlating alerts, devices, users, evidence, and automated investigation results into a single incident. Defender automatically investigates supported events and suspicious entities, helping analysts quickly identify impacted assets, suspicious processes, and malicious files. Reviewing incidents daily reduces attacker dwell time and enables fast remediation steps such as isolating devices or approving automated remediation actions. If this review is not done regularly, threats may persist longer, increasing the chances of data exposure, lateral movement, or system disruption. |
| 8 | + |
| 9 | +This supports the Zero Trust **Assume Breach** principle by ensuring constant monitoring, rapid response, and thorough investigation to limit the blast radius of any intrusion. |
| 10 | + |
| 11 | +### Where to investigate and remediate |
| 12 | +You can view and investigate incidents in the following areas of the Microsoft Defender portal: |
| 13 | + |
| 14 | +- **Incidents & alerts → Incidents** — provides correlated alerts, assets, investigations, and evidence from across your environment. |
| 15 | + [Investigate incidents in Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents) |
| 16 | +- **Incident details page** — shows alerts, affected devices, user accounts, mailboxes, and automated investigation results. |
| 17 | + [View the details and results of an automated investigation](https://learn.microsoft.com/en-us/defender-endpoint/autoir-investigation-results) |
| 18 | +- **Automated investigations** — includes information about suspicious entities and remediation actions automatically performed or awaiting approval. |
| 19 | + [Investigate incidents in Microsoft Defender for Endpoint](https://learn.microsoft.com/en-us/defender-endpoint/investigate-incidents) |
9 | 20 |
|
10 | 21 | ## Reference |
11 | | -[Investigate incidents in Microsoft Defender for Endpoint](https://learn.microsoft.com/en-us/defender-endpoint/investigate-incidents) |
| 22 | +- [Investigate incidents in Microsoft Defender for Endpoint](https://learn.microsoft.com/en-us/defender-endpoint/investigate-incidents) |
| 23 | +- [Investigate incidents in Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents) |
| 24 | +- [View the details and results of an automated investigation](https://learn.microsoft.com/en-us/defender-endpoint/autoir-investigation-results) |
0 commit comments