Loading...

New Incident Graph view in Microsoft 365 Defender

New Incident Graph view in Microsoft 365 Defender

The new incident graph helps you quickly understand and visualize the full timeline and related entities of an attack by connecting the different suspicious entities with their related assets such as users, devices, mailboxes and applications. The graph presents a holistic view of how an attack spread through an environment over time, where it started and how far the attacker went. 

 

 

Animation1.gif

 Play the attack over time

 

Now you will be able to:

  • See how the incident’s alerts are connected
    With one glance you can see the connection of alerts to the impacted assets in your organization. 
  • Pivot to alerts directly from the graph
    You can view the alerts right from the graph page and quickly drill down to view more details. 
  • Open the entity details directly from the graph
    You can view the entities details without losing orientation directly from the graph and act on them with response options like file delete, device isolation, etc.
  • Highlight the entities related to an alert
    Easily see which entities are related to which alerts and how they are part of the story of the attack. 

To easily investigate the incident and to help get you oriented, you can select specific alerts for which you want to highlight relevant entities.

 

Idan_Pelleg_0-1630571753395.png

 Highlight specific nodes on the graph based on the alert

 

You can drill down to each alert directly from the graph as well as open the entity side pane.

This will allow you to review the entity details and take remediation actions, such as deleting a file or isolating a device.

 

Idan_Pelleg_1-1630571863612.png

 

So now you can review, investigate and remediate attacks while seeing the full story of the attack right away and understand how the entites are connected to each other.

The incident graph in Microsoft 365 Defender is available from the new Graph tab of an incident .

 

See also

 

 

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Unleash the Power of Insights: Azure Resource Graph Power BI Data Connector Now Generally Available

The Azure Resource Graph Power BI Data Connector is now generally available, providing Azure users with a powerful tool that allows them to ga...

6 months ago

Manage Approvals Programmatically with Microsoft Teams Graph APIs | Public Preview

Microsoft Teams has released the public preview of its Approvals Graph APIs, enabling developers to programmatically create and manage approva...

6 months ago

Microsoft Graph API for SharePoint Pages | Now Generally Available

Developers can now take advantage of the general availability of the Microsoft Graph API for SharePoint pages. The API enables developers to i...

6 months ago

Changes to Microsoft Graph Presence and Meeting Notifications | Microsoft 365 Developer Blog

Microsoft Graph is undergoing changes to its notifications for presence and online meeting resources. Specifically, these changes will remove ...

7 months ago

Microsoft Copilot (Microsoft 365): Bring the latest from your organization into your Word chats with Microsoft Copilot Graph-grounded search

Microsoft Copilot is a powerful tool available in Microsoft 365 that allows users to bring the latest insights and information from their orga...

7 months ago

SharePoint: SharePoint Premium content AI Graph API in Beta (formerly known as Syntex)

In an effort to enhance the functionality of SharePoint Premium content AI capabilities (formerly known as Syntex models), Microsoft is releas...

7 months ago

Microsoft Copilot (Microsoft 365): Bring the latest from your organization into your Word chats with Microsoft Copilot Graph-grounded search

Microsoft Copilot is a powerful tool that allows Word chat users to get answers to their queries with the help of data and insights from the M...

7 months ago

Register for the Graph API webinar on April 23

If you want to learn how to use Microsoft's Graph API to access information on Windows known issues and product lifecycle, then mark April 23r...

7 months ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy