Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Microsoft Defender incidents to tickets. Read Microsoft Defender XDR incidents using Microsoft Graph and create company-scoped support incidents. Current availability: Implemented; Graph acceptance required. Before you start. Company administrator or TLS owner; a dedicated provider application for this company. A separate test tenant or approved test records and company responders who can verify results. Defender entitlement and an Entra application with SecurityIncident.Read.All application permission and tenant admin consent. Step 1. In the customer tenant, register a dedicated server application. Grant only SecurityIncident.Read.All for this incident-read workflow and record the secret expiry. Step 2. In Company > Security > Microsoft Defender, save the tenant ID, client ID and secret. Choose minimum severity, ticket creation and approved recipients. Step 3. Choose Verify read access. The adapter uses client credentials and Microsoft Graph v1.0 security/incidents with bounded paging; it does not isolate devices or change provider incidents. Step 4. Enable sync and use Sync now for a known approved incident. Confirm provider incident ID, affected company, title, severity and linked ticket. Step 5. Review credentials-compromise evidence and assign a responder. Remediation stays with authorized analysts in the provider; the connector does not infer theft from a device alert. Step 6. Acknowledge and resolve in the Security workspace with a resolution note. Close the support ticket after remediation and verify subsequent provider updates do not create duplicates. Now verify the result. A known provider finding creates exactly one company security event and one linked ticket when its severity qualifies. Repeat the same event and verify there is no duplicate ticket or responder notification. Pause the connection, verify no further polling, and check wrong-company API access is denied. If you get stuck. 403: confirm application permission, tenant consent and Defender entitlement. The legacy Intune entry is a separate read-check workflow; it does not replace this incident connector. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.