Understanding incident response and management
An incident in M365D is a collection of correlated alerts and data that together makes up the story of an attack. As mentioned throughout this book, Microsoft 365 services and applications generate alerts when they detect suspicious or malicious activity occurring. While individual alerts do provide valuable information on a completed or active attack, a modern attack often relies on using various techniques against different types of entities. The result is several alerts for several entities in your environment.
Piecing this information together manually to gain the necessary insights can be both time-consuming and challenging, which is why M365D aggregates the alerts and the associated information into an incident, as illustrated in the following diagram:
Figure 18.2 – The correlation of entities, associated information, and alerts with an incident
By grouping the alerts into an incident, it provides...