Forum Discussion
stianhoydal
Jan 04, 2022Brass Contributor
No option to tune analytics rule with Microsoft 365 Defender connector
Greetings, i have been working with a few different customers and when trying to configure the Defender for O365 alert "Email messages containing malicious URL removed after delivery", however there ...
- Jan 04, 2022You can't update those rules as it uses an integrated bi-directional sync engine.
The best way is to use automation rules to update these incidents based on certain conditions.
Thijs Lecomte
Jan 04, 2022Bronze Contributor
I always work for an MSP that runs a SOC.
You can setup priority for automation rules.
I close the incidents first and then only sync them
You can setup priority for automation rules.
I close the incidents first and then only sync them
stianhoydal
Jan 04, 2022Brass Contributor
I will try to do this and see if it works. Thanks for answers 🙂