Skip to main content
Retrieves the properties and relationships of an incident object.
  • Least privileged Microsoft Graph permission to access the action via application: SecurityIncident.Read.All.
  • Higher privileged Microsoft Graph permission to access the action via application: SecurityIncident.ReadWrite.All.
External DocumentationTo learn more, visit the Microsoft Defender XDR documentation.

Parameters

Example Output

Workflow Library Example

Get Incident with Microsoft Defender Xdr and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop