Jul 29 2021
10:52 AM
- last edited on
Nov 03 2021
03:58 AM
by
TechCommunityAP
Jul 29 2021
10:52 AM
- last edited on
Nov 03 2021
03:58 AM
by
TechCommunityAP
API connections and permissions for Azure Sentinel Playbooks (microsoft.com)
In addition to being a Security Information and Event Management (SIEM) tool, Azure Sentinel is a Security Orchestration, Automation, and Response (SOAR) platform. Automation takes a few different forms in Azure Sentinel, from automation rules that centrally manage the automation of incident handling and response, to playbooks that run predetermined sequences of actions to provide powerful and flexible advanced automation to your threat response tasks. In this blog we will be focusing on playbooks and understanding application programming interface (API) permissions, connections, and connectors in Azure Sentinel playbooks.