Microsoft Security | Microsoft Graph
An API that connects multiple Microsoft services, enabling data access and automation across platforms
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I'm trying to close a Defender Incident via Graph API.
I'm using the following info for the determination field:
So, i hardcoded it:
def close_alert(token, incident_id, resolving_comment, analyst):
logging.info(f"Closing Defender Incident {incident_id}")
# This is correct according to the API
api_endpoint = f"{DEFENDER_GRAPH_ENDPOINT}/{incident_id}"
headers = {
"Content-Type": "application/json",
"Authorization": f"Bearer {token}"
}
patch_data = {
"status": "resolved",
"classification": "falsePositive",
"assignedTo": analyst,
"resolvingComment": resolving_comment
}
if defender_determination:
patch_data["determination"] = "notMalicious"
try:
response = requests.patch(api_endpoint, headers=headers, json=patch_data)
if response.status_code == 200:
logging.info(f"Incident {incident_id} closed successfully")
return True
else:
logging.error(f"Failed to close incident ({response.status_code}): {response.text}")
logging.error(f"Payload sent: {patch_data}")
return False
except Exception as e:
logging.error(f"Error closing incident: {e}")
return False
and my code output looks like the following:
INFO:root:Closing Defender Incident 1866
ERROR:root:Failed to close incident (400): {"error":{"code":"InvalidRequestBody","message":"Request body is incorrect","innerError":{"date":"2025-09-24T11:34:21","request-id":"892b1add-d3ae-488f-b19a-092ff40ab956","client-request-id":"892b1add-d3ae-488f-b19a-092ff40ab956"}}}
ERROR:root:Payload sent: {'status': 'resolved', 'classification': 'falsePositive', 'assignedTo': 'analystname', 'resolvingComment': 'Closed from test script', 'determination': 'notMalicious'}
I already tested everything without "determination" field and it works flawlessly.
If i set determination to "malware" it works, but the other fields doesnt.
I've also tried with both versions: v1.0 and beta.
I'm really stuck, can you help me ?
An API that connects multiple Microsoft services, enabling data access and automation across platforms