Message Center

MC1477993Case Management in Microsoft Defender

Summary

Microsoft Defender introduces native Case Management to unify threat investigations, assign analysts, track SLAs, and capture notes in one workspace. Launching in public preview September 2026, it integrates with existing workflows and permissions, enhancing security team coordination and response efficiency without requiring manual migration.

More information

What and why:

Microsoft Defender is introducing native Case Management to help security teams investigate and resolve threats faster while reducing tool sprawl. Teams can manage investigations, assign analysts, monitor resolution SLAs, and capture investigation notes in a unified case experience.

Security teams often coordinate investigations across multiple tools, making it harder to maintain context, track ownership, and drive timely resolution. Case Management brings these activities into Microsoft Defender, helping teams streamline investigations and manage response work in one place.

Beginning with Incident Cases, the experience combines alerts, attack stories, affected assets, and evidence with the workflows teams use to assign work, collaborate, and track progress through resolution.

Rollout schedule:

  • Public preview begins: September 23, 2026.
  • Public preview rollout completion: early October 2026.

How this will affect your organization:

Who is affected

  • Microsoft Defender customers with Microsoft 365 E5, E7, Defender Suite and all standalone SKUs (MDE P2, MDO P2, MDA, MDI, MDB) and Microsoft Sentinel 
  • Security administrators, SOC analysts, incident responders, and SOC leads using Microsoft Defender for investigation and response.

Services affected

  • Microsoft Defender and existing Microsoft Sentinel incident workflows and integrations used with Incident Cases.

Case Management enables your organization to:

  • Manage investigations in one place: Bring together Microsoft Defender XDR signals and, when enabled, third-party data in a native Defender case workspace.
  • Establish clear ownership: Assign analysts and keep investigation notes with the case.
  • Track timely resolution: Monitor resolution SLAs and progress.
  • Preserve existing workflows: Existing incident-based workbooks, automation, playbooks, and integrations continue to function with Incident Cases.
  • Retain existing access controls: Incident permissions and access scoping carry over to Incident Cases.

For example, a SOC team investigating ransomware can use the case experience to track active investigations, assign analysts, monitor resolution SLAs, and keep relevant investigation notes with each case. 

Action required / Recommendations:

No manual migration or reconfiguration of existing incident workflows is required to begin using the Case experience. Each Incident Case maps one-to-one to an Incident during this phase.

To prepare:

  • Review how your SOC assigns investigations, captures notes, and tracks resolution targets.
  • Familiarize analysts with the Cases experience and update internal operating guidance.
  • Evaluate existing workflows and integrations as part of your preview adoption.

Additional Considerations

Initial scope: This launch begins with Incident Cases for incident response, with a one-to-one relationship between an Incident Case and an Incident.

Blog: Reimagining Case Management in Microsoft Defender | Microsoft Community Hub 

Demo video: https://aka.ms/casedemovideo

Learning docs: Case management in the Microsoft Defender portal - Microsoft Defender XDR | Microsoft Learn