Forum Discussion

AndrewX's avatar
AndrewX
Iron Contributor
May 18, 2022

SecurityAlert doesn't include important alert details

In the MS 365 Defender, we have an alert generated on "Granted mailbox permission" activity.  This event shows up in the SecurityEvent and OfficeActivity $tables, over in Log Analytics.

 

In OfficeActivity, it holds all the information about who did it, and who they did it to.

 

In SecurityAlerts, it only includes the "who did it" information, but not the "who they did it to" information.

 

This means Analysts can't use Sentinel for investigation, and have to go off to other portals to get more info and it means we can't write playbooks using the Sentinel Alerts trigger.

 

 

Are we missing something?

5 Replies

  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    AndrewX I believe this is the reason the new Microsoft 365 Defender data connector (currently in preview) was created.  It will allow you to ingest more information from the various defender products if you need them.

    • AndrewX's avatar
      AndrewX
      Iron Contributor
      So for now shall we keep using the other portals, where the information is already available?

      I just wish we could create alerts/notifications using playbooks for these events. Looks like ill have to write a custom Kusto query in LA and create an $1.50 alert based on it for now.
      • GaryBushey's avatar
        GaryBushey
        Bronze Contributor
        I'm saying the new data connector will copy the information from Defender and put into MS Sentinel so you can write the query to return all the data you want in it

Resources