An API that connects multiple Microsoft services, enabling data access and automation across platforms
The provided documentation confirms these supported behaviors, but it does not document Microsoft Graph /security/incidents behavior specifically for incidents from secondary Microsoft Sentinel workspaces.
Supported facts from the documentation:
- Microsoft Sentinel incidents can exist in both primary and secondary workspaces in the Defender portal.
- In the Defender portal, Incidents shows incidents from different workspaces in a unified queue, and the view can be filtered by workspace.
- For secondary workspaces, incidents created in that workspace are synced between that workspace in the Azure and Defender portals.
- Incident creation and alert correlation remain separate between workspaces. Incidents in secondary workspaces don't include data from other workspaces or from Defender XDR.
- For primary workspaces, Defender XDR incidents are synced with Microsoft Sentinel and support bi-directional incident updates between Azure and Defender portals.
The only Microsoft Graph-specific statement in the provided documentation is about API coverage for alerts v2:
- Sentinel-generated alerts aren't returned by the v2 API unless the Microsoft Sentinel workspace is connected to the Microsoft Defender portal.
The documentation provided does not state:
- whether
GET /security/incidentsreturns incidents from secondary Sentinel workspaces - whether the Graph incident payload contains a documented property for the originating Sentinel workspace
- whether Graph supports filtering incidents by originating workspace
- whether updates to secondary-workspace Sentinel incidents are exposed through Graph
- whether such incidents can be updated through
PATCH /security/incidents/{incidentId}
References: