A new operational unit for security work, beginning with incident response
Security work extends beyond the signal
Identifying a threat, exposure, or data risk is only the start. Security teams still need to assign ownership, bring together the right context, coordinate investigation and response, document decisions, track actions, and maintain accountability through resolution.
That work is not identical across organizations. Each team has its own responsibilities, processes, service-level commitments, and automation. Security teams need a work model they can adapt to how their organization operates, rather than forcing every security matter through a fixed workflow.
The operating model is also changing as AI agents take on more investigation and response work. Analysts, automation, and agents need a shared workspace where work can be delegated, reviewed, and advanced with the right context and human oversight.
Introducing the Case: the operational unit that brings together security context, people, process, automation, and actions to manage security work through resolution.
Introducing Case Management in Microsoft Defender
We are introducing Case Management in Microsoft Defender, starting with Incident Cases, your new home for incident response. Incident Cases bring together the familiar incident experience with powerful new case capabilities, combining alert correlation, response actions, workflow management, collaboration, automation, and lifecycle tracking in a single working experience. Incident Cases become the primary working entity for incident response in Microsoft Defender. They bring the context analysts rely on, including the attack story, alerts, affected assets, evidence, and response information, into the same workspace used to assign work, coordinate the response, track progress, and maintain the operational record.
Incident Cases build on the Defender Incident experience and the customer investments around it. The result is not a separate ticket layered on top of an investigation. It is one place to understand the security matter and drive the work required to resolve it.
Figure 1. An Incident Case brings investigation context and operational workflow into one experience.
One workspace for the complete response
Case Management expands the incident response experience around the work security teams need to perform, not only the information they need to review.
Adapt the workflow to how your organization operates
Security teams can shape Case records and lifecycle management around their operating model. Custom fields and custom statuses allow teams to capture organization-specific information and reflect their processes. SLA policies track targets such as acknowledgement, escalation, and resolution times based on attributes such as status, severity, and team.
Investigate, collaborate, and act in context
The Incident Case keeps the investigation context and operational workflow together. Analysts can work with the attack story, alerts, assets, and evidence while managing ownership, status, findings, comments, attachments and tasks from the same Case. Case creation and updates can also trigger automation and playbooks, helping teams apply consistent handling as work progresses.
Maintain accountability from creation through closure
Case activity provides a record of changes and actions throughout the lifecycle. Case data can also support reports and dashboards across lifecycle, ownership, status, severity, classification, and other Case attributes, giving security leaders greater visibility into how work moves through the organization.
VIDEO: https://aka.ms/casedemovideo
Video 1. Analysts manage the Case lifecycle while retaining Defender investigation context.
Bringing protection and operations closer together
Case Management is part of Defender’s Integrated Security Operations Center (ISOC) experience, which unifies security operations across protection, investigation, and response. By bringing key SIEM capabilities like cases, workbooks, automation, and reporting together in one platform, Defender helps organizations strengthen security, improve operational efficiency, and build the foundation for agentic security. Learn more in the [ISOC announcement].
Designed for work shared by people and agents
Project Perception introduced Microsoft's direction for an agentic security system designed for the realities of AI. Case Management is a foundational component of that vision, providing a shared operational workspace where analysts and AI agents collaborate on the same security matter, with agent work connected directly to investigation context, workflow, and human oversight.
The first integration links agentic sessions to Incident Cases for the Investigation Agent workflow. From the Case, analysts can connect relevant agentic work to the investigation and see when a session requires human attention. The direction is to expand this approach to additional agentic playbooks and Case types over time.
As analysts delegate more work to agents, the Case can provide the shared context in which people, automation, and agents contribute to the same security outcome, with human review remaining part of the workflow.
Figure 2. The analyst stays in control of the agentic security workflows happening in the case.Looking ahead, this foundation can extend to additional agentic playbooks and Case types—from exposure remediation to threat intelligence—while preserving the context, participants, and processes each workflow requires.
Built for a smooth transition from Incidents
Incident Cases are designed to preserve existing customer workflows and investments while introducing the Case experience.
- Existing Incident-based workbooks, workflows, automations, playbooks (logic apps), and integrations continue to function with Incident Cases.
- Existing Incident APIs continue to work on top of the Case schema. New Case-only properties are available through the Case API.
- Incident Cases use the existing Incident role-based access control model, with Incident permissions and scoping carried over to Cases.
- Each Incident Case has a one-to-one mapping with an Incident during this phase, and no manual migration or reconfiguration is required to begin using the Case experience.
Detailed compatibility and transition guidance are available in Microsoft Learn, including information for APIs, automation, reporting, permissions, and integrations.
Availability and get started
Incident Cases in Microsoft Defender will be available in public preview beginning September 23,2026.
To learn more and start using Case Management: