Forum Discussion
mschcomm
Jun 21, 2021Copper Contributor
Automation rules on Microsoft Defender Connector
Hi guys, Just configured the "Microsoft 365 Defender (Preview)" connector within Sentinel which automatically receives alerts from Defender for Endpoint and MCAS. Is there anyway to auto supress ...
- Jun 21, 2021In order to close MDE alerts, select 'All' for the Analytic Rule filter and use Microsoft Product or title conditions to run your rules
Rod_Trent
Microsoft
Jun 21, 2021You can use an Automation Rule to auto-close the Incident. Otherwise, you would need to tune MDE or MCAS to not send the alert.
- mschcommJun 21, 2021Copper ContributorDoesn't that need to be linked to an analytic rule? or do they run also without?
- Thijs LecomteJun 21, 2021Bronze ContributorIn order to close MDE alerts, select 'All' for the Analytic Rule filter and use Microsoft Product or title conditions to run your rules
- mschcommJun 21, 2021Copper Contributor
Thijs Lecomte Thanks Thijs! I totally missed the fact that you could use it without a specific rule.