Microsoft Graph Security API Alert Ingestion Integration For Security Operations
Create Security Incidents automatically from Microsoft Graph Security API alerts.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 75 | -75 |
| 163 days of no change | ||
| 2025-11-14 | 74 | +1 |
| 28 days of no change | ||
| 2025-10-16 | 73 | +1 |
| 41 days of no change | ||
| 2025-09-04 | 71 | +2 |
| 44 days of no change | ||
| 2025-07-21 | 70 | +1 |
| 31 days of no change | ||
| 2025-06-19 | 69 | +1 |
| 51 days of no change | ||
| 2025-04-28 | 68 | +1 |
| 3 days of no change | ||
| 2025-04-24 | 67 | +1 |
| 27 days of no change | ||
| 2025-03-27 | 66 | +1 |
| 24 days of no change | ||
| 2025-03-02 | 65 | +1 |
| 23 days of no change | ||
| 2025-02-06 | 64 | +1 |
About
The Microsoft Graph Security API is an intermediary service (or broker) that provides a single programmatic interface to connect multiple security providers (Native to Microsoft and ServiceNow Partners).
The Microsoft Graph Security Alert Ingestion integration allows you to automatically retrieve alerts from multiple security providers, convert them into security incidents, and enable automated response actions.
Key Features
This integration includes the following key features:
- Discovery of Microsoft Graph Security Alerts that are candidates for security incidents and automate the creation of security incidents.
- Mapping of alert fields to security incident fields.
- Aggregation of similar alerts to existing open security incidents instead of creating duplicate security incidents.
- Validate your mapping with a preview of the alert field values in a security incident.
- Automatic alert status update for SIR incident creation and closure.
- Setup scheduled ingestion of alerts to create security incidents periodically.