POWERSHELL COMMAND
Merge-XdrIncident
Merges multiple incidents into a single incident in Microsoft Defender XDR.
Combines multiple incidents into one incident in Microsoft Defender XDR. All incidents must exist before merging. The cmdlet validates each incident ID before proceeding. This operation requires confirmation due to its high impact.
Syntax
Merge-XdrIncident [-IncidentIds] <int[]> [-Comment] <string> [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-IncidentIds
| Property | Value |
|---|---|
| Type | Int32[] |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Array of incident IDs to merge. Must contain at least 2 incident IDs. All incidents will be validated before the merge operation.
-Comment
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Comment explaining the reason for merging the incidents. This will be recorded in the incident history.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The JSON body for the merge operation will be displayed.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before executing the merge operation.
Examples
Merge-XdrIncident -IncidentIds 2821, 2823 -Comment "Related phishing attacks"
Merges incidents 2821 and 2823 with a comment.
Merge-XdrIncident -IncidentIds 100, 101, 102 -Comment "Same threat actor campaign"
Merges three incidents into one.
$incidents = 2821, 2823, 2825
Merge-XdrIncident -IncidentIds $incidents -Comment "Coordinated attack"
Merges multiple incidents using a variable.
Output
Type: Object
Returns the result of the merge operation from the API.