Microsoft Entra Suite Tech Accelerator
Aug 14 2024, 07:00 AM - 09:30 AM (PDT)
Microsoft Tech Community

RE: Tracking Security Incidents linked to an Intune device

Brass Contributor



I already have a similar request asking about this but wanted to change the scoping of the query being asked.


Is it possible with KQL to 'track' ANY Security Incidents (primarily generated from an Analytics Rule) that are associated or linked to an 'Intune' Device?


I know the 'SecurityIncident' table can locate the 'Incidents' but which table(s) can I perform a JOIN on to find those Incidents associated with an 'Intune' Device?

1 Reply