Dec. 25, 2023, 5:16 p.m. | /u/Vast_Independent5995

cybersecurity www.reddit.com

I’ve been dabbling with Sentinel playbooks lately, specifically for incidents that are detected by defender. I’ve got all the right analytic workbooks, connectors and playbooks from the content store setup. I have the right permissions in the resource group to do this. I have the sentinel managed identity setup with the right permissions to run the playbooks. Any time I try to use a playbook that hits defender for an action such as “run full virus scan” or “block mde …

connectors cybersecurity defender identity incidents managed permissions playbooks resource run sentinel siem store workbooks

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Officer Hospital Laguna Beach

@ Allied Universal | Laguna Beach, CA, United States

Sr. Cloud DevSecOps Engineer

@ Oracle | NOIDA, UTTAR PRADESH, India

Cloud Operations Security Engineer

@ Elekta | Crawley - Cornerstone

Cybersecurity – Senior Information System Security Manager (ISSM)

@ Boeing | USA - Seal Beach, CA

Engineering -- Tech Risk -- Security Architecture -- VP -- Dallas

@ Goldman Sachs | Dallas, Texas, United States