Describe incidents and incident management capabilities
As stated at the beginning of the section describing Secure Score, the Microsoft 365 Defender portal can be used for security posture management within your entire Microsoft 365 tenant for identity, devices, and applications. This includes incidents created based on potential threats and vulnerabilities and the management of those incidents.
Within the Microsoft 365 Defender portal, there is an Incidents & alerts menu that will assign incidents on potential threats that need further investigation. You can manage these incidents through the incident response process within the portal, as shown in Figure 12.18:
You can also configure alerts based on incidents to assign to the specific incident response teams. The dashboard for Alerts is shown in Figure 12.19: