Forum Discussion
NCreminder
Jul 19, 2022Copper Contributor
defender incidents are automatically re-opening
Hi, Recently, I've observed that defender incidents are automatically changing the status from Resolved to Active. When I checked the comments on the incident, I can clearly see that automation ...
HeikeRitter
Microsoft
Jul 22, 2022Hi,
can you explain more about it please. Who is first resolving the incident? Manually done before the automation starts its investigation?
can you explain more about it please. Who is first resolving the incident? Manually done before the automation starts its investigation?
Sean_Tickle
Aug 04, 2022Copper Contributor
HeikeRitterI'm also experiencing this issue recently.
The alerts are sent into Sentinel via the Defender 365 connector and are closed on the Sentinel side, which i can then see is reopened several minutes later by automation in the Defender portal itself.
I've attached a screenshot below, they all pretty much follow the same problem.
Any ways of getting around this?