Having issues with Run-MDEAntiVirus Playbook

%3CLINGO-SUB%20id%3D%22lingo-sub-3073556%22%20slang%3D%22en-US%22%3EHaving%20issues%20with%20Run-MDEAntiVirus%20Playbook%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3073556%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20having%20issues%20getting%20the%20Run-MDEAntiVirus%20playbook%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20created%20it%20using%20the%20Github%20template%2C%20assigned%20the%20managed%20instance%20rights%20to%20Sentinel%20and%20the%20Defender%20ATP.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20it%20is%20triggered%20I%20get%20the%20following%20error%20message.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MikePalmer75_0-1643269114804.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F342883i0E4CB9BD83A6721B%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22MikePalmer75_0-1643269114804.png%22%20alt%3D%22MikePalmer75_0-1643269114804.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20I%20can%20see%20the%20post%20command%20is%20not%20sending%20over%20the%20MDATPid.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MikePalmer75_1-1643269211493.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F342884i08DB7CEFCA1A53E6%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22MikePalmer75_1-1643269211493.png%22%20alt%3D%22MikePalmer75_1-1643269211493.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EThe%20information%20from%20the%20entries%20Get-Hosts%20does%20provide%20the%20host%20and%20the%20MDATPid%20information%20so%20I'm%20a%20little%20lost%20on%20what%20is%20going%20on.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20anyone%20help%20me%20please%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMike%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3073582%22%20slang%3D%22en-US%22%3ERe%3A%20Having%20issues%20with%20Run-MDEAntiVirus%20Playbook%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3073582%22%20slang%3D%22en-US%22%3EJust%20redeployed%20the%20playbook%20from%20Sentinel%20and%20output%20does%20not%20match%20the%20screenshots%20from%20the%20Github%20information%20-%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2FPlaybooks%2FRun-MDEAntivirus%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2FPlaybooks%2FRun-MDEAntivirus%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

 

I'm having issues getting the Run-MDEAntiVirus playbook working.

 

I have created it using the Github template, assigned the managed instance rights to Sentinel and the Defender ATP. 

 

When it is triggered I get the following error message.

MikePalmer75_0-1643269114804.png

 

From what I can see the post command is not sending over the MDATPDeviceId.

 

MikePalmer75_1-1643269211493.png

The information from the entries Get-Hosts does provide the host and the MDATPDeviceId information so I'm a little lost on what is going on.

 

Could anyone help me please?

 

Regards

 

Mike 

2 Replies
Just redeployed the playbook from Sentinel and output does not match the screenshots from the Github information - https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Run-MDEAntivirus



Raised a MS support call for this. It appears the templates in Sentinel are cached and not being refreshed from the Github content.