A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
1,427 questions with Microsoft Security | Microsoft Sentinel tags
How are hackers able to access the Calendar App to PHISH
First of all, I almost never use the Calendar App. Currently, I have discovered three separate postings to my Calendar that are obvious (to me) to be Phishing attempts. So, how do I stop this, and seek punishment for the "Hackers"?
Microsoft Security | Microsoft Sentinel
DCR Data Sources only showing in classic version
Hello, I'm using microsoft sentinel to ingest events into a custom table in log analytics, and the data source I'm using is something like "Custom-table_CL" where table is the name in log analytics. This data source can only be found in the…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Sentinel SIEM
How can I achieve multi-tenancy in Microsoft sentinel without them having sentinel that I can access via lighthouse, is there a different method? If a client wants me to monitor only their third party EDR and i already onboarded the same third party on…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Update Data Connector causing error "The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time period."
Hi, Could you please help to make CCF data connector able to complete "Update Data Connectors" successfully. DCR "Lookout Mobile Threat Detection Connector (via Codeless Connector Framework) (Preview)" (deployed as solution from here…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Sentinel workspace cannot be created
Hi, I had a workspace and I have added it to Sentinel. Everything was working fine. Then I created another LAW on another subscription within the same tenant. I could not add it to Sentinel. I have moved all my resources to the new subscription including…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel Question in Practice Exam for SC 200
Question: You have an Azure subscription that uses Microsoft Sentinel. You create a user named Admin1. You need to ensure that Admin1 can add playbooks in Microsoft Sentinel. The solution must follow the principle of least privilege. Which role should…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Unable to connect Microsoft Sentinel workspace to Defender portal as Primary workspace
Hello, We are unable to connect a Microsoft Sentinel workspace to the Microsoft Defender portal and set it as the Primary workspace. Error shown in Microsoft Defender portal: "Failed to connect primary workspace" "Couldn't connect…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
CCF Data Connector - Pass Generated Access Token from POST API to Subsequent GET API in Azure CCP Connector
We are developing a CCP connector in Azure and are facing an issue with API authentication flow implementation. Scenario The first API endpoint is a POST request used to generate an access_token. This API requires a secret key to be passed in…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel Keeper Security Connector Fails to perform app registration
When trying to Follow the keeper instructions and push the button to deploy the app registration of the Keeper Push Connector, I receive the following error message. Keeper support said I needed to contact Microsoft. I have an active Global Admin role…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel Stuck in a Loop in the Defender Portal
In the microsoft defender portal with sentinel, i have connected, disconnected and waited 30 minutes, and reconnected the SIEM workspace. if i go to sentinel and any of the tabs in defender, it just loops to the connectors page as if the workspace is not…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How to create email alert based on KQL query result regularly in Sentinel ?
Using the Sentinel Platform, how to create email alert based on KQL query result regularly in Sentinel? This is the KQL Query I am trying to get some alerting immediately when there is any result returned. SigninLogs | where TimeGenerated >…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How to connect the SAP JAVA single Stack Application to MS sentinel using agentless connector
Hi, We required to integrate a SAP JAVA application with MS sentinel using Agentless connector. Cloud you please help us to provide any KBA or the Guide or steps to perform this integration. It is helpful for us to fulfill the project needs Thanks and…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel
Hello there, My first question is if content hu moved to Defender from Sentinel. Then trying to find sentinel optimization workbook and I dont see it and most important the SignInLogs table doesn not appear in Defender. I enabled Entra ID diagnostic…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Datalake in Sentinel is not working properly since completing this course: TechWorkshop L300: Understanding Sentinel data lake and graph
Datalake in Sentinel is not working properly since completing this course: TechWorkshop L300: Understanding Sentinel data lake and graph in Microsoft. I have no access to Datalake tables or Datalake features since completing this course. Part of the…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How do I find my Windows Advertising Identifier number
I want to find my MAID number for my computer so that I can enter in California's new DROP program.
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
CCF Data Connector – Pagination and Checkpoint handing with PageToken & PageStartTime
Hi Team, I am currently developing a custom Azure Sentinel Data Connector via the Common Connector Framework (CCF) for Google SecOps APIs. I am currently facing challenges related to pagination handling and state management for subsequent…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Migration Path for [DEPRECATED] VMware Carbon Black Cloud (using Azure Function) Sentinel Connector
Hello, We have been using the VMware Carbon Black Cloud (using Azure Function) Sentinel Connector for many years to gather logs from Carbon Black. The current connector is deprecated now though, and the only option that has been added to the Content Hub…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Issue with Sentinel Watchlist visibility
There are multiple internal watchlist which we use but today out of a sudden their visibility is missing. What can be the reason, this is causing multiple fails in playbooks too
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Data lake configuration
Data lake creation fails with "Something went wrong" after multiple failed provisioning attempts. Microsoft.Kusto provider was not registered during initial attempts - now registered but the error persists. No orphaned ADX clusters found.…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How to make a URL from Logic App Clickable
Hello. I have a Logic App Playbook that automatically sends me email notifications for new Azure Sentinel Incidents. However when these mails come in, I notice the URL link to the incident is not clickable. I have to manually copy and paste it into a…
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
Microsoft Teams | Microsoft Teams for business | Other
Additional features, settings, or issues not covered by specific Microsoft Teams categories
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems