Forum Discussion
mschcomm
Jun 21, 2021Copper Contributor
Automation rules on Microsoft Defender Connector
Hi guys, Just configured the "Microsoft 365 Defender (Preview)" connector within Sentinel which automatically receives alerts from Defender for Endpoint and MCAS. Is there anyway to auto supress ...
- Jun 21, 2021In order to close MDE alerts, select 'All' for the Analytic Rule filter and use Microsoft Product or title conditions to run your rules
mschcomm
Jun 21, 2021Copper Contributor
Doesn't that need to be linked to an analytic rule? or do they run also without?
Thijs Lecomte
Jun 21, 2021Bronze Contributor
In order to close MDE alerts, select 'All' for the Analytic Rule filter and use Microsoft Product or title conditions to run your rules
- mschcommJun 21, 2021Copper Contributor
Thijs Lecomte Thanks Thijs! I totally missed the fact that you could use it without a specific rule.