Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community
Auto-Triage Infrequent Country Alerts using MCAS & Power Automate
Published Sep 08 2020 09:09 AM 7,664 Views
Microsoft

By: @Caroline_Lee & @Sebastien Molendijk 

 

Update on where to find our Power Automate templates: we will post all of our templates on GitHub (https://github.com/microsoft/Microsoft-Cloud-App-Security/tree/master/Playbooks) including instructions on how to import the templates into your Power Automate instance. Comment below with any questions!

 

Welcome back to the Automation in Cloud App Security series with Sebastien & Caroline. For those of you who are reading for the first time, this series covers advanced scenarios for our Microsoft Cloud App Security (MCAS) users; providing Power Automate flows to solve the most common customer asks the Customer Experience team sees today.  

 

Go check out our first blog to see how we auto-remediated information protection alerts https://aka.ms/MCAS/Auto-Blog. In today’s post, we will be covering how to use Power Automate in Cloud App Security to dismiss Infrequent Country alerts. 

 

The Infrequent Country Alert in Cloud App Security is a popular detection for many companies. The alert triggers when there is sign-in activity outside of normal user locations. For example, imagine you have an employee who normally works out of the New York corporate office but then you see there is a sign-in activity for that person from China, you probably want to investigate this type of alert. In MCAS, you can tune the policy by scoping it to specific users, groups and by the type of sign in activity (see below template) 

 

Caroline_Lee_0-1599576920133.png

 

Activity from infrequent country template in MCAS 

We’ve also recently published an anomaly detection alerts investigation guide to aid administrators in distinguishing true positives vs. benign true positives vs. false positives. But what about when employees go on vacation? Or are travelling outside of the country for work? How do you manage the volume of alerts especially for large enterprises? 

 

 

We have developed a new flow in Power Automate to answer these questions. If you haven’t configured a Power Automate Flow in MCAS before, check out these steps in our documentation. So, how does this flow work? Essentially, when an infrequent country alert gets triggered, we’ll send it to Power Automate. In the flow, it will look at a couple of different details: 

 

  1. The user profile (job title, department, email address, etc.) 
  2. If the user has an out of office (OOO) message enabled 
  3. Any groups the user is a part of 

 

Based off these details, we can set conditions to auto-resolve the alert or request further investigation. The logic will be: If the user has an OOO message, then resolve the alert. You could also add more conditions around the user groups. For example, if you have a user who is part of a sensitive group such as Security Administrators, you could add logic to say if the user has no OOO message and is in the Security Admin group, then you may want to investigate the alert. 

 

As folks start to take leave for vacation or staycation, this flow could help to save time in the alert investigation as admins will be able to focus on the most critical activities and lessen the sheer volume of alerts seen in MCAS. Keep an eye out for our next post and comment below if there are any other topics you’d like us to cover! 

5 Comments
Version history
Last update:
‎Nov 02 2021 04:47 PM
Updated by: