Forum Discussion

esanya2280's avatar
esanya2280
Copper Contributor
May 04, 2026

Microsoft Defender Incident – Handling incident severity change.

 

I am polling incidents via Microsoft Graph API every 5 minutes, initially filtering out Low/Informational incidents.

Later, some low severity incidents are updated to High/Medium severity.

Is there any built-in mechanism in Defender for tracking severity transitions?

 

 

No RepliesBe the first to reply