defender_get_incident
Retrieve a Microsoft Defender incident's full stored details including severity, status, classification, owner, tags, comments, and timestamps. Start incident analysis here without following merged incidents.
Instructions
Get one incident as it is stored: severity, status, classification, determination, owner, custom tags, comment thread, timestamps, and redirectIncidentId when it was merged into another. The starting point of incident analysis; it does not follow merges (use defender_resolve_incident for that).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| incident_id | Yes | The incident ID, as shown in the Defender portal and the Graph API. |