New Incident Graph view in Microsoft 365 Defender

Published Sep 02 2021 08:22 AM 10.1K Views

The new incident graph helps you quickly understand and visualize the full timeline and related entities of an attack by connecting the different suspicious entities with their related assets such as users, devices, mailboxes and applications. The graph presents a holistic view of how an attack spread through an environment over time, where it started and how far the attacker went. 




 Play the attack over time


Now you will be able to:

  • See how the incident’s alerts are connected
    With one glance you can see the connection of alerts to the impacted assets in your organization. 
  • Pivot to alerts directly from the graph
    You can view the alerts right from the graph page and quickly drill down to view more details. 
  • Open the entity details directly from the graph
    You can view the entities details without losing orientation directly from the graph and act on them with response options like file delete, device isolation, etc.
  • Highlight the entities related to an alert
    Easily see which entities are related to which alerts and how they are part of the story of the attack. 

To easily investigate the incident and to help get you oriented, you can select specific alerts for which you want to highlight relevant entities.



 Highlight specific nodes on the graph based on the alert


You can drill down to each alert directly from the graph as well as open the entity side pane.

This will allow you to review the entity details and take remediation actions, such as deleting a file or isolating a device.




So now you can review, investigate and remediate attacks while seeing the full story of the attack right away and understand how the entites are connected to each other.

The incident graph in Microsoft 365 Defender is available from the new Graph tab of an incident .


See also




Senior Member

In the See also links above, I can't see the docs until I remove the "review" prefix from the URL.  i.e. change* to*
Is there something about these links that requires the review prefix, or do I need to register elsewhere for access to that?
(If there is a better place to ask this type of question, please point me to that, I couldn't find it.)




Thanks @OwenAllen_BlueVoyant I fixed the links!

Occasional Visitor

Hi, is this feature still in preview?

In the following URL it says its in preview,

but in my demo environment, the "Graph" tab doesnt have "(Preivew)" written on it.


I was just curious if its been GA or not because its such a great feature.


@Shawn225 Yes, this new view is currently in public preview, GA coming up soon for sure :)

Version history
Last update:
‎Sep 02 2021 11:09 AM
Updated by: