Forum Discussion

Kithu147's avatar
Kithu147
Copper Contributor
Jan 26, 2024

Create playbook to release requested quarantined emails?

I can't find any information on possibility of releasing quarantined emails of the alert created by Microsoft Defender XDR. Such as "User requested to release a quarantined message" and "User requested to release a quarantined message involving one user".

 

I see there are playbooks created with Microsoft Defender Connector. Have conditions in such as non-high confidence only and not reported by more than one user.

Would Azure logic app be able to do this, if so, some guide is appreciated?

Resources