calling AD group in analytical rule in place of watchlist

Brass Contributor

Hi Team,

 

can it be possible to use AD group in analytical rule in place of watchlist?

 

if possible then how it can be done ?

2 Replies
IdentityInfo
| where GroupMembership in ""
| distinct AccountName, GroupMembership


please check this