Forum Discussion

Alfred_Schreuder's avatar
Alfred_Schreuder
Copper Contributor
Feb 12, 2024

Microsoft Defender XDR / Defender for Endpoint data connectors inconsistent failures

Hello,

 

We are deploying our SOC (Sentinel) environments via Bicep. Now the Defender XDR (

MicrosoftThreatProtection) and Defender for Endpoint (
MicrosoftDefenderAdvancedThreatProtection) data connectors are failing to deploy inconsistantly. It seems to be a known issue due to the following posts:
- https://github.com/Azure/SimuLand/issues/23
- https://github.com/Azure/Azure-Sentinel/issues/5007
 
Next to this issue I see almost no development on the data connectors API, is there some news to be spread how to enable data connectors automated in the future, since it seems to be moving to Content Hub. It is hard to find any docs about how to deploy this for example via Bicep!?
 
Also I have a question regarding 'Tenant-based Microsoft Defender for Cloud (Preview)' data connector. We deploy this now via GenericUI data connector kind, but this has no option to enable it via automation. Same as the question in the previous paragraph, how would this be made possible?
No RepliesBe the first to reply

Resources