Aug 27 2021
01:23 AM
- last edited on
Jan 14 2022
03:25 PM
by
TechCommunityAP
Aug 27 2021
01:23 AM
- last edited on
Jan 14 2022
03:25 PM
by
TechCommunityAP
Hi,
I work in a small security team, and we don't have 24/7 till now, so I would like to find a way to lock users which are High Risk users.
By now we get an email alert of those.
What I would like to know is if I can create any kind of workflow that whenever a user has a High Risk, sends the email and locks the user on Active Directory, until a team member will be able to check it manually.
Is there any way to achieve it considering we don't have yet Sentinel (neither we can right now).
Thanks
Aug 27 2021 07:52 AM
Aug 27 2021 10:37 AM - edited Aug 27 2021 10:41 AM
@dmarquesgn What subscription do you have? I may state the obvious here but have you looked at AAD Identity Protection?
How To: Configure and enable risk policies