Forum Discussion

leoszalkowski's avatar
leoszalkowski
Copper Contributor
Jan 07, 2020

Azure Active Directory Identity Protection Playbook?

I have the Azure AD IP enabled on some of our tenants. 

 

I was wondering if it's possible to have a playbook run on these types of alerts?

3 Replies

  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor
    It is currently the 7th highest idea in the UserVoice site but no comments on it from Microsoft
  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    leoszalkowski If you are referring to adding a Playbook to the "Create incidents based on Azure Active Directory Identity Protection" alert rule created from the template with the same name, then no it is not possible.

     

    It is rumored to be on Microsoft's radar to get this working but you will probably be better off handling those alerts, and others that fall under the Microsoft Security rule type, in the originating system at least for now.

     

Resources