Does Microsoft Graph /security/incidents return Microsoft Sentinel incidents from secondary workspaces?

Mahmud Hanif 0 Reputation points
2026-10-08T07:32:24.8066667+00:00

We are evaluating the Microsoft Graph Security API in a Microsoft Sentinel multi-workspace scenario.

The environment consists of:

one Microsoft Sentinel workspace onboarded to the Microsoft Defender portal as the primary workspace

another Microsoft Sentinel workspace onboarded as a secondary workspace

The secondary workspace creates its own Sentinel alerts and incidents through Sentinel analytics rules. These incidents are visible in the Defender portal.

We would like to clarify the supported behavior of the following Microsoft Graph API:

GET https://graph.microsoft.com/v1.0/security/incidents

Main question

Does this endpoint return incidents originating from an onboarded secondary Microsoft Sentinel workspace, in addition to incidents from the primary workspace and native Defender XDR incidents?

We have reviewed the Microsoft Graph documentation. It states that Sentinel must be onboarded to the Defender portal in order to view Sentinel alerts and incidents through Microsoft Graph. However, we could not find documentation specifying whether this also includes incidents from secondary workspaces..

If secondary-workspace incidents are returned:

  1. Is there a documented property in the Graph response that identifies the originating Sentinel workspace?

Can incidents be filtered by originating workspace through the Graph API?

Are subsequent updates to those incidents also exposed through Graph?

Can such incidents also be updated through PATCH /security/incidents/{incidentId}?

We are looking for confirmation of the supported product behavior, ideally with a corresponding Microsoft documentation reference.

Microsoft Security | Microsoft Graph
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-10-08T07:32:43.12+00:00

    The provided documentation confirms these supported behaviors, but it does not document Microsoft Graph /security/incidents behavior specifically for incidents from secondary Microsoft Sentinel workspaces.

    Supported facts from the documentation:

    • Microsoft Sentinel incidents can exist in both primary and secondary workspaces in the Defender portal.
    • In the Defender portal, Incidents shows incidents from different workspaces in a unified queue, and the view can be filtered by workspace.
    • For secondary workspaces, incidents created in that workspace are synced between that workspace in the Azure and Defender portals.
    • Incident creation and alert correlation remain separate between workspaces. Incidents in secondary workspaces don't include data from other workspaces or from Defender XDR.
    • For primary workspaces, Defender XDR incidents are synced with Microsoft Sentinel and support bi-directional incident updates between Azure and Defender portals.

    The only Microsoft Graph-specific statement in the provided documentation is about API coverage for alerts v2:

    • Sentinel-generated alerts aren't returned by the v2 API unless the Microsoft Sentinel workspace is connected to the Microsoft Defender portal.

    The documentation provided does not state:

    • whether GET /security/incidents returns incidents from secondary Sentinel workspaces
    • whether the Graph incident payload contains a documented property for the originating Sentinel workspace
    • whether Graph supports filtering incidents by originating workspace
    • whether updates to secondary-workspace Sentinel incidents are exposed through Graph
    • whether such incidents can be updated through PATCH /security/incidents/{incidentId}

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.