Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community

RE: Tracking Security Incidents linked to an Intune device

Brass Contributor

Hello,

 

I already have a similar request asking about this but wanted to change the scoping of the query being asked.

 

Is it possible with KQL to 'track' ANY Security Incidents (primarily generated from an Analytics Rule) that are associated or linked to an 'Intune' Device?

 

I know the 'SecurityIncident' table can locate the 'Incidents' but which table(s) can I perform a JOIN on to find those Incidents associated with an 'Intune' Device?

1 Reply