Microsoft improving the Azure Sentinel REST API

I was looking the latest changes MS made to the Azure Sentinel REST API (available at and noticed that they now have an entire section called “incidents” that can be used just as “cases” could before.

This makes more sense since, during the beta, Alerts created “cases” but now they create “incidents” . This will make it easier to use and understand the REST API. From my testing anytime I have made a reference to “cases” in my REST API URL, I can change it to “incidents” and it will work just the same.

