| title | Update incident |
|---|---|
| description | Update the properties of an incident object. |
| ms.date | 2/25/2025 |
| author | LeonardoMele-MSFT |
| ms.localizationpriority | medium |
| ms.subservice | security |
| doc_type | apiPageType |
Namespace: microsoft.graph.security
Update the properties of an incident object.
[!INCLUDE national-cloud-support]
Choose the permission or permissions marked as least privileged for this API. Use a higher privileged permission or permissions only if your app requires it. For details about delegated and application permissions, see Permission types. To learn more about these permissions, see the permissions reference.
[!INCLUDE permissions-table]
[!INCLUDE rbac-security-alerts-apis-write]
PATCH /security/incidents/{incidentId}| Name | Description |
|---|---|
| Authorization | Bearer {token}. Required. Learn more about authentication and authorization. |
| Content-Type | application/json. Required. |
[!INCLUDE table-intro]
| Property | Type | Description |
|---|---|---|
| assignedTo | String | Owner of the incident, or null if no owner is assigned. Free editable text. |
| classification | microsoft.graph.security.alertClassification | The specification for the incident. The possible values are: unknown, falsePositive, truePositive, informationalExpectedActivity, unknownFutureValue. |
| customTags | String collection | Array of custom tags associated with an incident. |
| description | String | Description of the incident. |
| determination | microsoft.graph.security.alertDetermination | Specifies the determination of the incident. The possible values are: unknown, apt, malware, securityPersonnel, securityTesting, unwantedSoftware, other, multiStagedAttack, compromisedAccount, phishing, maliciousUserActivity, notMalicious, notEnoughDataToValidate, confirmedUserActivity, lineOfBusinessApplication, unknownFutureValue. |
| displayName | String | The incident name. |
| severity | microsoft.graph.security.alertSeverity | Indicates the possible impact on assets. The higher the severity, the bigger the impact. Typically, higher severity items require the most immediate attention. The possible values are: unknown, informational, low, medium, high, unknownFutureValue. |
| resolvingComment | string | User input that explains the resolution of the incident and the classification choice. It contains free editable text. |
| status | microsoft.graph.security.incidentStatus | The status of the incident. The possible values are: active, resolved, redirected, unknownFutureValue. |
| summary | String | The overview of an attack. When applicable, the summary contains details of what occurred, impacted assets, and the type of attack. |
If successful, this method returns a 200 OK response code and an updated microsoft.graph.security.incident object in the response body.
The following example shows a request.
PATCH https://graph.microsoft.com/v1.0/security/incidents/29
Content-Type: application/json
{
"classification": "TruePositive",
"determination": "MultiStagedAttack",
"customTags": [
"Demo"
]
}[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
[!INCLUDE sample-code] [!INCLUDE sdk-documentation]
The following example shows the response.
Note: The response object shown here might be shortened for readability.
HTTP/1.1 200 OK
Content-Type: application/json
{
"@odata.context": "https://graph.microsoft.com/v1.0/$metadata#security/incidents/$entity",
"id": "29",
"tenantId": "cfcdbe43-297b-4c6b-ac7e-8d7f6befb514",
"status": "active",
"incidentWebUrl": "https://security.microsoft.com/incident2/29/overview?tid=cfcdbe43-297b-4c6b-ac7e-8d7f6befb514",
"redirectIncidentId": null,
"displayName": "Multi-stage incident involving Execution & Command and control on one endpoint",
"createdDateTime": "2026-01-22T12:09:23.1433333Z",
"lastUpdateDateTime": "2026-02-25T16:29:33.1Z",
"assignedTo": "admin@contoso.com",
"classification": "truePositive",
"determination": "multiStagedAttack",
"severity": "high",
"customTags": [
"Demo"
],
"systemTags": [],
"description": "Microsoft observed Raspberry Robin worm activity spreading through infected USB devices on multiple endpoints in your environment.",
"lastModifiedBy": "API-App:admin@contoso.com",
"resolvingComment": null,
"summary": "Defender Experts has identified malicious activity. This incident has been raised for your awareness and should be investigated as usual.",
"priorityScore": 100,
"comments": []
}