Jun 29 2022 05:19 AM
Hello everybody,
I need to configure a Sentinel playbook to send emails to users when an incident is created regarding their account.
I have created a playbook that uses Identity Protection incidents creation as trigger but I'm not currently able to set the right parameter to address automatically the alert to the user the incident refers to.
I don't need to set an address statically but the playbook has to fetch the user email address from the incident automatically and use it as recipient.
Which parameter or expression should I use?
I hope you can kindly help me with this.
Best regards.
Jun 29 2022 07:12 AM
@frank_df You definitely need to get both the user name and the UPN from the Incident Entities. Something like the following...
Feb 14 2023 11:30 PM
Feb 15 2023 03:17 AM
@Prashali_Shinde
Yes, I achieved that!
Here is my current configuration:
NB: I added a condition because I had to send an email or another according to the UPN suffix. You can skip straight to the last step ("send an email").
Feb 22 2023 01:37 AM