Respond to security incidents
Cross-Product Incident Response
CoreCorrelate mail, data, workload, SaaS, identity, and Sentinel evidence into one defensible attack story, then contain the assets that the evidence shows are compromised.
Aligned to SC-200 skills measured as of July 28, 2026; product behavior verified September 18, 2026.
Why this matters
A single campaign can start in email, steal an identity, spread to endpoints, and reach cloud resources. Local cleanup in one portal may remove the first artifact while leaving sessions, persistence, or downstream access active.
Must Know
- Defender for Office 365 evidence identifies campaign messages, recipients, delivery, clicks, and remediation status.
- Purview alerts describe sensitive-data and user activity; correlate them with identity and endpoint evidence before attributing cause.
- Defender for Cloud workload alerts pivot through the affected cloud resource and its process, network, and identity context.
- Defender for Cloud Apps investigations center on app, user, session, and activity evidence; Microsoft Entra risk signals strengthen identity decisions.
- Defender for Identity exposes directory reconnaissance, credential theft, and lateral movement relationships.
- Security Copilot can organize evidence and propose pivots, but analysts must validate its claims against source records.
- Use Sentinel incident entities, timelines, ownership, status, and tasks to correlate complex attacks and maintain a durable case across handoffs.
- Case management preserves owner, status, tasks, findings, evidence, actions, and handoff context.
Compare and Distinguish
- An alert is evidence from a detection; an incident correlates alerts and entities into an investigation; a case preserves coordinated handling context.
- Containment limits ongoing harm; remediation removes or reverses malicious changes; recovery returns assets to trusted operation.
- AI-generated summaries accelerate triage but remain hypotheses until validated against the underlying evidence.
Scenario examples
- Scenario: Email, identity, and endpoint alerts describe one campaign. Think: investigate the correlated incident and contain across affected domains.
- Scenario: Embedded Security Copilot proposes a root cause. Think: verify cited entities, timestamps, and actions before remediation.
- Scenario: A handoff crosses shifts. Think: preserve ownership, status, evidence, tasks, and rationale in case management.
Exam traps
- Blocking a sender does not retract delivered mail or remediate a clicked account.
- A valid credential does not make a risky sign-in legitimate.
- A shared IP or product-generated correlation is a lead whose relationship and timing still need review.
- An AI summary is not an action record and cannot prove isolation or exfiltration.
Key takeaways
- Follow shared entities and timestamps across product boundaries.
- Contain confirmed identity, device, session, and workload paths, then verify eradication before recovery.
- Keep the incident record current enough for another team to continue without guessing.
How it works
- Defender XDR correlates supported alert and entity evidence into an incident attack story.
- Responders pivot into the source product for detailed activity and return action outcomes to the incident record.
Objects and administrative surfaces
- Unified incident queue and attack story in the Microsoft Defender portal.
- Microsoft Sentinel incident entities, timeline, tasks, comments, owner, and status.
- Source-product evidence for email, identity, endpoint, app, Purview, and cloud-workload remediation.
When to use it
- Use product-specific evidence to investigate the stage it observes, then correlate across the incident.
- Use Security Copilot to accelerate summaries and pivots when every material claim can still be checked against source telemetry.
Security and governance implications
- Preserve sensitive-data, identity, device, and workload evidence under the case access policy.
- Record justification and outcome for broad identity or workload containment.
Troubleshooting signals
- When alerts appear unrelated, compare canonical entity IDs, timestamps, IPs, sessions, and process ancestry.
- When an automated action and an AI summary disagree, rely on the action record and primary event evidence.
More detail
- Defender for Office 365 evidence identifies campaign messages, recipients, delivery, clicks, and remediation status.
- Purview alerts describe sensitive-data and user activity; correlate them with identity and endpoint evidence before attributing cause.
- Defender for Cloud workload alerts pivot through the affected cloud resource and its process, network, and identity context.
- Defender for Cloud Apps investigations center on app, user, session, and activity evidence; Microsoft Entra risk signals strengthen identity decisions.
- Defender for Identity exposes directory reconnaissance, credential theft, and lateral movement relationships.
- Security Copilot can organize evidence and propose pivots, but analysts must validate its claims against source records.
- Use Sentinel incident entities, timelines, ownership, status, and tasks to correlate complex attacks and maintain a durable case across handoffs.
- Case management preserves owner, status, tasks, findings, evidence, actions, and handoff context.
Ready for the quiz?
- What evidence distinguishes a delivered phishing message from a compromised recipient?
- How do you bound a cloud-workload response to the affected resource?
- Which case fields prevent duplicate work during a shift handoff?
Related objectives
- D2.1.S1 — Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption
- D2.1.S2 — Investigate and remediate threats or compromised entities identified by Microsoft Purview
- D2.1.S3 — Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections
- D2.1.S4 — Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps
- D2.1.S5 — Investigate and remediate compromised identities that are identified by Microsoft Entra ID
- D2.1.S6 — Investigate and remediate security alerts from Microsoft Defender for Identity
- D2.1.S7 — Investigate and remediate alerts and incidents identified by Microsoft Sentinel
- D2.1.S8 — Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot
- D2.1.S9 — Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement
- D2.1.S10 — Manage security incidents by using case management
Learn more
- Official SC-200 study guide
- Investigate Defender XDR incidents
- Defender for Office 365 investigation
- Defender for Cloud Apps investigation
- Remediate Microsoft Entra risks
- Defender for Identity alert investigation
- Sentinel incident investigation
- Security Copilot incident investigation
- Microsoft Defender portal incidents and alerts