Microsoft Entra Tech Accelerator
Jun 27 2023, 08:00 AM - 12:00 PM (PDT)
Microsoft Tech Community

RE: Tracking Security Incidents linked to an Intune device




I already have a similar request asking about this but wanted to change the scoping of the query being asked.


Is it possible with KQL to 'track' ANY Security Incidents (primarily generated from an Analytics Rule) that are associated or linked to an 'Intune' Device?


I know the 'SecurityIncident' table can locate the 'Incidents' but which table(s) can I perform a JOIN on to find those Incidents associated with an 'Intune' Device?

1 Reply