Incidents
Microsoft Sentinel incidents group related alerts and entities into investigation records that analysts can triage, assign, classify, and close.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Supported | Reference |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Incidents are operational records, not desired-state configuration. Manage incident state through REST/Graph automation, not Terraform. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |