What is the correct way to update the determination field on a Microsoft Defender incident via Graph API? PATCH /security/incidents/{incidentId} currently returns 400 InvalidRequestBody.”

João Castanheira 5 Reputation points
2025-09-24T11:57:07.0033333+00:00

I'm trying to close a Defender Incident via Graph API.

I'm using the following info for the determination field:
User's image

So, i hardcoded it:

def close_alert(token, incident_id, resolving_comment, analyst):
    logging.info(f"Closing Defender Incident {incident_id}")
    
   # This is correct according to the API
    api_endpoint = f"{DEFENDER_GRAPH_ENDPOINT}/{incident_id}"
    headers = {
        "Content-Type": "application/json",
        "Authorization": f"Bearer {token}"
    }

    patch_data = {
        "status": "resolved",
        "classification": "falsePositive",
        "assignedTo": analyst,
        "resolvingComment": resolving_comment
    }
    if defender_determination:
        patch_data["determination"] = "notMalicious"
    try:
        response = requests.patch(api_endpoint, headers=headers, json=patch_data)
        if response.status_code == 200:
            logging.info(f"Incident {incident_id} closed successfully")
            return True
        else:
            logging.error(f"Failed to close incident ({response.status_code}): {response.text}")
            logging.error(f"Payload sent: {patch_data}")
            return False
    except Exception as e:
        logging.error(f"Error closing incident: {e}")
        return False

and my code output looks like the following:

INFO:root:Closing Defender Incident 1866
ERROR:root:Failed to close incident (400): {"error":{"code":"InvalidRequestBody","message":"Request body is incorrect","innerError":{"date":"2025-09-24T11:34:21","request-id":"892b1add-d3ae-488f-b19a-092ff40ab956","client-request-id":"892b1add-d3ae-488f-b19a-092ff40ab956"}}}
ERROR:root:Payload sent: {'status': 'resolved', 'classification': 'falsePositive', 'assignedTo': 'analystname', 'resolvingComment': 'Closed from test script', 'determination': 'notMalicious'}

I already tested everything without "determination" field and it works flawlessly.

If i set determination to "malware" it works, but the other fields doesnt.

I've also tried with both versions: v1.0 and beta.

I'm really stuck, can you help me ?

Microsoft Security | Microsoft Graph
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.