1. Microsoft Learn. (2023). Investigate incidents with Microsoft Sentinel.
Section: "Assigning incidents and changing status and severity"
Quote/Content: "Assign an incident to an owner to take responsibility for its remediation. You can also assign incidents to a group... When you assign an incident to an owner
the owner's name appears in the incident details in the Owner field." This document explicitly describes assigning an incident as the method for transferring responsibility.
2. Microsoft Learn. (2023). Automatically create incidents from Microsoft security alerts.
Section: "Introduction"
Quote/Content: "Microsoft Sentinel allows you to automatically create incidents each time an alert is triggered in a connected Microsoft security service." This confirms that incident creation rules are for generating new incidents
not managing existing ones.
3. Microsoft Learn. (2023). Create custom analytics rules to detect threats.
Section: "Rule settings in the Analytics rule wizard - General tab"
Quote/Content: "Scheduled query rules run queries on a schedule
looking for events that might indicate a threat." This shows that scheduled query rules are for threat detection and alert creation
not incident management.