Last week at Ignite, we announced the public preview of URL detonation in Azure Sentinel. This blog post provides more details on its benefits and how to enable it.
Security operations center (...
I agree this feature seems very "preview" at the moment, which is a pity since a consistent result would allow my team to skip the step of sending the URL to an external API for a screenshot. I have an example below where an incident is generated by a NRT rule triggering on blocked URLs from our firewalls logging to CommonSecurityLog.
The incident investigation has the DetonationFinalUrl entry but no screenshot.
If I view the information in the incident object as seen by a playbook there is an URL to the DetonationScreenshot.