You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
You deploy Azure Sentinel.
You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
In Microsoft Sentinel, playbooks are Azure Logic Apps that automate responses to alerts or incidents. To use an existing Logic App as a playbook in Sentinel, it must start with the ''Microsoft Sentinel alert'' trigger. This trigger allows Sentinel to call and pass alert details to the Logic App automatically.
When an existing Logic App has a manual trigger, it cannot be invoked directly by Sentinel. Therefore, the first step is to modify the trigger to replace the manual trigger with the ''When a response to an Azure Sentinel alert is triggered'' trigger. After that, you can link it within Sentinel incidents or automation rules.
This process is detailed in Microsoft Defender XDR and Sentinel documentation under ''Connect a Logic App to Sentinel as a playbook.''
Hence, the correct answer is D. Modify the trigger in the logic app.
Glynda
4 days agoRoxane
9 days agoLizbeth
14 days agoTyra
19 days agoJordan
25 days agoWillard
30 days agoRoxane
1 month agoGlynda
1 month agoTora
2 months agoLaquanda
2 months agoShalon
2 months agoJutta
2 months agoAileen
2 months agoStaci
2 months agoJuliana
3 months agoMaryann
3 months agoDorsey
3 months ago