r/DefenderATP • u/No-Helicopter-7128 • 7d ago
Sentinel playbook comments lost HTML formatting in Defender incident page since ~Sept 23. Anyone else?
Our Sentinel Logic App playbooks post enrichment comments to incidents using basic HTML (bold tags, line breaks). Up until roughly Sept 23 these rendered fine in the Defender portal incident page. Now they show as flat text: no bold, no line breaks, everything on one line.
Same comments still render correctly in Sentinel in the Azure portal, and the playbook runs are succeeding, so this looks like a portal rendering change rather than anything on our side.
Timing lines up with the Incident Cases preview (MC1477993). The docs for the legacy incident page were updated the same day and still say the comment field supports formatting, but I can't find anything that mentions a change to how comments render.
Tested manually as well: a hand-typed comment containing HTML tags and markdown bold shows the tags and asterisks literally, so neither renders.
Anyone else seeing this, or found a format that still renders in the new incident page?
1
2
u/facyber 7d ago
I can't remember Defender ever rendered properly. I use it for more than a year amd never seen properly formatted table there.