Nov 24 2020 12:53 AM
Hello,
We would like create an Sentinel alert rule for the builtin alert in PIM: "Roles are being assigned outside of Privileged Identity Management" Are these builtin alerts traceble in the AD Audit Logs?
Regards, Erik
Dec 14 2020 02:15 PM
@Erik_Snijder I think you just might need to use the MCAS Alerts for this, and integrate MCAS to Sentinel