Can someone provide some detail on the behaviour of ‘disable alert tracking’ for the M365 Defender Incidents connector?
Am I right in thinking that if an alert or incident is changed after ingestion on Defender’s side it will update (as opposed to creating new) on Google SecOps SOAR side?
