Edit

Migrate Microsoft Sentinel incident creation rules to alert grouping rules

Use this guide when you onboard a Microsoft Sentinel workspace to the Defender portal and want to preserve Sentinel-like incident creation behavior for Defender alerts.

What alert grouping rules do

Alert grouping rules in Microsoft Defender control how related alerts are grouped into incidents. They provide the Defender-side behavior controls that align with incident creation behavior used in Microsoft Sentinel Incident creation rules.

When you choose Retain Sentinel incident creation behavior for XDR alerts during onboarding, Defender applies equivalent grouping behavior as part of onboarding.

Prerequisites

  • A Microsoft Sentinel workspace with incident creation settings rules configured.
  • Permission to onboard the workspace in the Defender portal.
  • Permission to view and manage detection rules in Microsoft Defender.

Migrate incident creation behavior during onboarding

To migrate incident creation behavior when you onboard a Microsoft Sentinel workspace to the Defender portal, follow the directions in Connect Microsoft Sentinel to the Microsoft Defender portal. During the onboarding flow, make sure you do the following:

  1. Set the workspace you want to use as the primary workspace.
  2. In the onboarding dialog, select Retain Sentinel incident creation behavior for XDR alerts.

This option applies migration behavior during onboarding. Later changes to Sentinel rule grouping aren't continuously synced to Defender.

Validate migrated alert grouping rules

After onboarding finishes:

  1. Go to Settings > Microsoft Defender XDR > Alert grouping.
  2. Verify that expected rules are present and enabled.
  3. Open a migrated rule and confirm key behavior settings match your expected incident grouping outcomes.

Screenshot of the alert grouping rules page showing migrated rules in Microsoft Defender.

Validate incident and automation outcomes

  1. Trigger representative detections.
  2. Verify incident grouping still matches expected automation patterns.
  3. Validate playbooks, routing, and ticketing integrations that depend on incident behavior.
  4. Confirm incident title behavior matches your operational expectations. Incident titles might differ from Sentinel depending on correlation context.
  5. If manual incident merges are used in your process, validate those workflows. Manual merges can combine incidents that were originally kept separate.

To review correlation behavior and incident merges during investigation, see Alert correlation and incident merging in the Microsoft Defender portal.

The associated incidents view improves analyst context, but it doesn't change grouping rules by itself.

Screenshot of the incident graph filter showing associated incidents options.

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.