Forum Discussion
Cristian Calinescu
Nov 05, 2019Brass Contributor
Adding playbooks to Microsoft Security out-of-the-box alert rule templates
Hi all, I am trying to find a way to attach a playbook to the default Microsoft Security alert rules in Azure Sentinel. I am referring to the rules that automatically create Azure Sentinel incidents...
pemontto
Jul 16, 2020Brass Contributor
Hi Ofer_Shezaf this one has been open a while. Are we likely to get functionality where we can run automated responses for all rule types? It really breaks up workflows where they're intended to be managed in other tools (Jira, SNow). Operators now need to be eyes on glass in Sentinel as well.
The only workaround we're aware of is to write a scheduled rule (for each severity) that searches the SecurityAlert table
- Ofer_ShezafJul 16, 2020
Microsoft
pemontto : the feature is currently in private preview.
- ManvieJan 08, 2021Copper Contributor
Ofer_Shezaf Do you have an update on the progress for this feature ?
Thanks- Ofer_ShezafJan 10, 2021
Microsoft
Manvie : still in private preview, I hope we are getting closer to going public. We made major changes based on private preview input.