Trigger the Microsoft Defender for Endpoint capabilities from Related Links

  • Versão de lançamento: Australia
  • Atualizado 12 de mar. de 2026
  • 1 min. de leitura
  • Trigger a capability profile manually after reviewing a security incident from related links.

    Antes de Iniciar

    Role required: sn_si.admin or sn_si.analyst

    Procedimento

    1. Navigate to Security Incidents > Show All Incidents.
    2. Select the security incident that you want to review with the Microsoft Defender for Endpoint information.
    3. In the Related Links section, click Run EDR Profile(s).
    4. Browse and select a profile from the list of available profiles, and click Submit.
      The selected profile is triggered manually.
    5. Validate the work notes and activities section.
    6. View the tags, and validate the data in the related lists.