Forum Discussion
AnalystGuy
Aug 12, 2020Copper Contributor
Getting Office 365 Security Events and Incidents in Sentinel
I’ve created a custom detection in Office 365’s security portal that generated an incident, but that incident is not showing up in Azure Sentinel. I’ve done queries in Sentinel via the...
Thijs Lecomte
Aug 26, 2020Bronze Contributor
I see
Then I would advise you to connect MDATP to Sentinel (https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protection)
And enable the analytics rule - Create incidents based on Microsoft Defender Advanced Threat Protection alerts
Then I would advise you to connect MDATP to Sentinel (https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protection)
And enable the analytics rule - Create incidents based on Microsoft Defender Advanced Threat Protection alerts
AnalystGuy
Sep 11, 2020Copper Contributor
Thank you I'll investigate...