Forum Discussion

Andres_Iniesta's avatar
Andres_Iniesta
Copper Contributor
Feb 20, 2023

Avoiding duplicates in Sentinel when connecting M365 Defender

Hi,

according to the documentation here: Microsoft 365 Defender integration with Microsoft Sentinel | Microsoft Learn

To avoid duplicates in incident creation, it's recommended to "turn off all Microsoft incident creation rules for Microsoft 365 Defender-integrated products".

Does that mean the Analytics rules shown in the image?

Am I correct in this assumption? With those disabled(and the M365 Defender connector enabled), I'll get the incidents coming from all products through M365 Defender and not miss anything without getting duplicates?

 

Thank you in advance.

Andrés.

  • Hello!

    From your question and your answers, you got it right 🙂
  • Hello!

    From your question and your answers, you got it right 🙂
    • GDusautoir1775's avatar
      GDusautoir1775
      Copper Contributor
      Hello,
      But does that mean that Sentinel won't be the single pane of glass and the team will have to work across two different interfaces to deal with incidents?

Resources