What you need to know
Can an incident PDF omit assets or evidence items and still be an expected export?
Potentially affected
Authorized Microsoft Defender incident reviewers exporting incident information to PDF.
DSE recommendation
Record the PDF's selected sections, coverage limits and generation time alongside the incident reference.
Source facts
Defender’s incident PDF includes up to ten impacted assets of each asset type and up to one hundred evidence items. The export dialog lets the operator include or exclude incident information, with everything selected initially. A generated report is cached briefly, so exporting the same incident again soon can return the earlier PDF; Microsoft advises waiting a few minutes for a newer version. Microsoft Learn.
Applicability
Apply this review when a PDF is used for handoff, offline analysis or an investigation record. Distinguish the exported presentation from a claim that every asset and evidence item in the live incident is present.
DSE recommendation
Record the PDF’s selected sections, coverage limits and generation time alongside the incident reference. Ask the investigator to identify any material evidence outside the displayed limits and preserve an authorized reference to it separately. After significant incident updates, do not repeatedly download the file and assume each download represents newly generated content. Keep the original export when it forms part of the investigation history.
Verification
Compare the exported asset and evidence lists with the incident’s current scope, especially where a category exceeds the documented cap. Inspect the report after the cache interval when a refreshed version is required, and confirm that the intended recent change appears. Label differences as omitted coverage, operator-selected exclusions or an earlier snapshot rather than treating every mismatch as lost incident data. Retain the comparison with the handoff.
Official references
Microsoft Learn: Managing incidents and exporting PDF data. Source reviewed September 9, 2026.
Review the official source
Manage incidents in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE