Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

11302022 as incident response approval email

Open AcceleryntSecurityDev opened this issue 2 years ago • 13 comments

Change(s): New Playbook

Reason for Change(s): New Playbook

Testing Completed: Yes

AcceleryntSecurityDev avatar Dec 02 '22 05:12 AcceleryntSecurityDev

Hi,

  1. The name of the playbook may be too general - incident response approval email may be relevant to multiple scenarios.
  2. Why is Key Vault required? Can managed identity replace it?

lior-tamir avatar Dec 04 '22 07:12 lior-tamir

@manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Dec 07 '22 04:12 v-spadarthi

@lior-tamir

  1. I will update the playbook name.
  2. The key vault is used to store the client secret of the app registration used for http callouts to the graph api- there is not a connector for this, so managed identity cannot be used.

AcceleryntSecurityDev avatar Dec 07 '22 23:12 AcceleryntSecurityDev

@manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Dec 13 '22 06:12 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-mchatla avatar Dec 15 '22 05:12 v-mchatla

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-spadarthi avatar Dec 21 '22 04:12 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-spadarthi avatar Dec 23 '22 04:12 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks @manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Dec 28 '22 04:12 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks @manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Dec 29 '22 09:12 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks @manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Jan 03 '23 09:01 v-spadarthi

Hi @lior-tamir, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks @manishkumar1991 / @rahul0216 : Please have a look and provide your feedback. Thanks!

v-spadarthi avatar Jan 06 '23 04:01 v-spadarthi

Hi @lior-tamir, waiting for your response for author's comment. Thanks

v-atulyadav avatar Jan 11 '23 04:01 v-atulyadav

Hi @lior-tamir, @manishkumar1991, @rahul0216, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-mchatla avatar Jan 13 '23 04:01 v-mchatla

Hi @lior-tamir, @manishkumar1991, @rahul0216, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-mchatla avatar Jan 20 '23 05:01 v-mchatla

Hi @lior-tamir, @manishkumar1991, @rahul0216, Can you please review the comments from author and suggest if there is any alternate to this approach. Thanks

v-atulyadav avatar Jan 27 '23 04:01 v-atulyadav

Hi @manishkumar1991, @rahul0216, Can you please go through the authors comments and suggest if there is feasibility to use managed identity. Thanks

v-mchatla avatar Feb 01 '23 05:02 v-mchatla

Hi @manishkumar1991, @rahul0216, Can you please go through the authors comments and suggest if there is feasibility to use managed identity. Thanks

I will review it , please allow some time

manishkumar1991 avatar Feb 02 '23 10:02 manishkumar1991

Hi @AcceleryntSecurityDev, Could you please address the Rahul's comments. Thanks

v-mchatla avatar Feb 08 '23 04:02 v-mchatla

@AcceleryntSecurityDev Please share screenshot of successful run of the playbook as well.

rahul0216 avatar Feb 08 '23 10:02 rahul0216