Forum Discussion
smavrakis
Nov 25, 2025Copper Contributor
How to stop incidents merging under new incident (MultiStage) in defender.
Dear All We are experiencing a challenge with the integration between Microsoft Sentinel and the Defender portal where multiple custom rule alerts and analytic rule incidents are being automatically...
- Dec 15, 2025
For any1 Interested Microsoft Announced, a way to stop this from happening
Basically the rule author needs to add #DONT_CORR# tag in the rule description.
jbmartin6
Nov 26, 2025Iron Contributor
Just go the the Alerts list instead of the Incidents list
- smavrakisDec 01, 2025Copper Contributor
The question is specifically about controlling or disabling the automatic incident correlation/merging behavior in Defender XDR for Sentinel‑generated alerts so that distinct custom detections remain as separate incidents so “just use the Alerts list” does not address the problem or the requirements described.
- jbmartin6Dec 02, 2025Iron Contributor
Ah I see what you mean now. I think you would have to do that outside of Defender, I've never seen or heard of a mechanism to do that inside Defender.