MC1477993 - Case Management in Microsoft Defender
Microsoft 365 Message Center announcement MC1477993.
MS Message Center's Summary
Microsoft is introducing native Case Management in Microsoft Defender to unify threat investigations, assign analysts, track service level agreements, and capture notes in one workspace. The public preview rolls out from late September to early October 2026. Administrators should review internal security operations procedures, familiarise analysts with the new interface, and evaluate existing workflows to prepare for the change.
- Administrator impact
- No direct administrator action is required.
- End user impact
- Security analysts will gain a unified workspace for managing threat investigations and tracking incident progress.
- Importance
- 3/10: This is a new preview feature that enhances security operations without requiring immediate configuration changes.
Microsoft Summary
Microsoft Defender introduces native Case Management to unify threat investigations, assign analysts, track SLAs, and capture notes in one workspace. Launching in public preview September 2026, it integrates with existing workflows and permissions, enhancing security team coordination and response efficiency without requiring manual migration.
- Message Center ID
- MC1477993
- Category
- stay Informed
- Severity
- normal
- Services
- Microsoft Defender XDR
- Tags
- New feature, Admin impact
- Published
- 2026-09-23
- Last updated
- 2026-09-23
- Expires
- 2026-11-30
[What and why:] Microsoft Defender is introducing native Case Management to help security teams investigate and resolve threats faster while reducing tool sprawl. Teams can manage investigations, assign analysts, monitor resolution SLAs, and capture investigation notes in a unified case experience. Security teams often coordinate investigations across multiple tools, making it harder to maintain context, track ownership, and drive timely resolution. Case Management brings these activities into Microsoft Defender, helping teams streamline investigations and manage response work in one place. Beginning with Incident Cases, the experience combines alerts, attack stories, affected assets, and evidence with the workflows teams use to assign work, collaborate, and track progress through resolution. [Rollout schedule:] Public preview begins: September 23, 2026. Public preview rollout completion: early October 2026. [How this will affect your organization:] Who is affected Microsoft Defender customers with Microsoft 365 E5, E7, Defender Suite and all standalone SKUs (MDE P2, MDO P2, MDA, MDI, MDB) and Microsoft Sentinel Security administrators, SOC analysts, incident responders, and SOC leads using Microsoft Defender for investigation and response. Services affected Microsoft Defender and existing Microsoft Sentinel incident workflows and integrations used with Incident Cases. Case Management enables your organization to: Manage investigations in one place: Bring together Microsoft Defender XDR signals and, when enabled, third-party data in a native Defender case workspace. Establish clear ownership: Assign analysts and keep investigation notes with the case. Track timely resolution: Monitor resolution SLAs and progress. Preserve existing workflows: Existing incident-based workbooks, automation, playbooks, and integrations continue to function with Incident Cases. Retain existing access controls: Incident permissions and access scoping carry over to Incident Cases. For example, a SOC team investigating ransomware can use the case experience to track active investigations, assign analysts, monitor resolution SLAs, and keep relevant investigation notes with each case. [Action required / Recommendations:] No manual migration or reconfiguration of existing incident workflows is required to begin using the Case experience. Each Incident Case maps one-to-one to an Incident during this phase. To prepare: Review how your SOC assigns investigations, captures notes, and tracks resolution targets. Familiarize analysts with the Cases experience and update internal operating guidance. Evaluate existing workflows and integrations as part of your preview adoption. Additional Considerations Initial scope: This launch begins with Incident Cases for incident response, with a one-to-one relationship between an Incident Case and an Incident. Blog: Reimagining Case Management in Microsoft Defender | Microsoft Community Hub Demo video: https://aka.ms/casedemovideo Learning docs: Case management in the Microsoft Defender portal - Microsoft Defender XDR | Microsoft Learn