Forum Discussion

Ricky Bryant's avatar
Ricky Bryant
Copper Contributor
Feb 12, 2020

Microsoft Threat Protection and MCAS

Hello!

 

I have a question regarding the integration between MTP and MCAS. Although we can see alerts flowing into MTP from MCAS, there doesn't appear to be alert/incident status updating between the two platforms. We have the Azure ATP integration enabled in MCAS as required in the listed prerequisites. Additionally, two-way updating appears to be working for our integration between Defender ATP and MTP. Is this a known issue, working as intended, or an issue with our instances?

 

Thank you,

Ricky

2 Replies

  • Razmi_Patel's avatar
    Razmi_Patel
    Brass Contributor

    Ricky Bryant did you get a response on this?

     

    I see that Azure ATP and Cloud App Security don't support what you are looking for but I can't find anything specific to MTP - 

    https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-mcas-integration

    "When using Azure ATP with Cloud app security, closing alerts in one service will not automatically close them in the other service. Decide where to manage and remediate alerts to avoid duplicated efforts."

     

    I'd like to see a statement and roadmap for which integrated portal to use. Its all very confusing

    • Ricky Bryant's avatar
      Ricky Bryant
      Copper Contributor

      Razmi_Patel I have not received a response to this and I agree, it would be awesome to see exactly which centralized dashboard we should be using and have that dashboard be able to close out alerts in the connected tools.

       

      Ricky

Resources