Skip to Content

MC1477993 Case Management in Microsoft Defender

Summary

  • Microsoft Defender is adding native Case Management to help security teams investigate and resolve threats in one place.
  • The initial scope is Incident Cases, combining alerts, attack stories, affected assets, evidence, ownership, notes, and progress tracking.
  • Affected users are security administrators, SOC analysts, incident responders, and SOC leads using Microsoft Defender and related Sentinel incident workflows.
  • Existing incident workflows, permissions, workbooks, automation, playbooks, and integrations continue to work; no migration or reconfiguration is required to start using the new experience.
  • IT should review SOC processes, brief analysts, and update operating guidance to prepare for preview adoption.

Primary Service: Defender XDR
Admin Impact: Medium
User Impact: Medium
Release Start: 23 Sept 2026
Release End: 01 Oct 2026
Services: Defender XDR, Security
Category: Stay informed
Tags: Admin Action, New Feature, Highlighted

History

9/23/2026 Item Added to Message Center

Microsoft Message

Microsoft Defender is introducing native Case Management to help security teams investigate and resolve threats faster while reducing tool sprawl. Teams can manage investigations, assign analysts, monitor resolution SLAs, and capture investigation notes in a unified case experience.

Security teams often coordinate investigations across multiple tools, making it harder to maintain context, track ownership, and drive timely resolution. Case Management brings these activities into Microsoft Defender, helping teams streamline investigations and manage response work in one place.

Beginning with Incident Cases, the experience combines alerts, attack stories, affected assets, and evidence with the workflows teams use to assign work, collaborate, and track progress through resolution.

Rollout schedule

  • Public preview begins: September 23, 2026.
  • Public preview rollout completion: early October 2026.

How this will affect your organization

Who is affected

  • Microsoft Defender customers with Microsoft 365 E5, E7, Defender Suite and all standalone SKUs (MDE P2, MDO P2, MDA, MDI, MDB) and Microsoft Sentinel
  • Security administrators, SOC analysts, incident responders, and SOC leads using Microsoft Defender for investigation and response.

Services affected

  • Microsoft Defender and existing Microsoft Sentinel incident workflows and integrations used with Incident Cases.

Case Management enables your organization to:

  • Manage investigations in one place: Bring together Microsoft Defender XDR signals and, when enabled, third-party data in a native Defender case workspace.
  • Establish clear ownership: Assign analysts and keep investigation notes with the case.
  • Track timely resolution: Monitor resolution SLAs and progress.
  • Preserve existing workflows: Existing incident-based workbooks, automation, playbooks, and integrations continue to function with Incident Cases.
  • Retain existing access controls: Incident permissions and access scoping carry over to Incident Cases.

For example, a SOC team investigating ransomware can use the case experience to track active investigations, assign analysts, monitor resolution SLAs, and keep relevant investigation notes with each case.

Action required / Recommendations

No manual migration or reconfiguration of existing incident workflows is required to begin using the Case experience. Each Incident Case maps one-to-one to an Incident during this phase.

To prepare:

  • Review how your SOC assigns investigations, captures notes, and tracks resolution targets.
  • Familiarize analysts with the Cases experience and update internal operating guidance.
  • Evaluate existing workflows and integrations as part of your preview adoption.

Additional Considerations

Initial scope: This launch begins with Incident Cases for incident response, with a one-to-one relationship between an Incident Case and an Incident.

Blog: Reimagining Case Management in Microsoft Defender | Microsoft Community Hub

Demo video: https://aka.ms/casedemovideo

Learning docs: Case management in the Microsoft Defender portal – Microsoft Defender XDR | Microsoft Learn