Forum Discussion
BillClarksonAntill
Sep 16, 2023Iron Contributor
TheHoff70 the analytics that are mapped to the playbook, have they been mapped with the appropriate entities for azure object IDs?
This will surface the specific information for the playbooks to fire properly against the alert when it is triggered?
Check out this link to further information
Map data fields to Microsoft Sentinel entities | Microsoft Learn
- TheHoff70Sep 18, 2023Brass ContributorI've been trying back and forth with both with different entity mappings like DNS domain+UPN, "Full Name" or domain+UPN but so far no luck.