Correlate Microsoft Defender alerts into linked Tines Cases
Build a workflow that polls Microsoft Graph for new/updated security alerts and incidents. For each, create or update a Tines case with the alert details and notes, and link cases that belong to the same incident. Maintain incident records for tracking. Deduplicate by alert/incident ID, handle pagination and token refresh, and retry transient Graph errors. Output the cases created/updated and their linkage.
What this prompt builds
Pull Defender alerts and incidents and build linked, context-rich cases automatically.
The problem
Defender generates a high volume of alerts that, viewed individually, hide the bigger incident, so analysts duplicate work and miss connections. Manually correlating related alerts is slow and inconsistent.
Solution and impact
This workflow retrieves Microsoft Graph security alerts and incidents and creates or updates Tines cases with detailed notes, linking related cases together. Analysts work consolidated incidents instead of isolated alerts, with full context preserved.
