Forum Discussion

DarrenP's avatar
DarrenP
Copper Contributor
Nov 23, 2021

"Azure DevOps Personal Access Token (PAT) misuse" rule - allow list?

Hi All

 

This is probably an easy one, but I cannot seem to locate how to do this.

 

I have a number of false-positives in Sentinel relating to the Analytics Rule "Azure DevOps Personal Access Token (PAT) misuse" - where I know the entity (User and IP).

 

How do I configure some kind of 'allow list' to stop getting these alerts?

 

Thanks

Darren