Skip to main content
Update the properties of an incident object. Supply only the values for properties that should be updated.
  • Least privileged Microsoft Graph permission to access the action via application: SecurityIncident.ReadWrite.All*.
External DocumentationTo learn more, visit the Microsoft Defender XDR documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Update Incident with Microsoft Defender Xdr and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop