Microsoft Flow & MS Defender ATP Integration - Demo
Автор: Ammar Hasayen
Загружено: 2019-05-31
Просмотров: 2584
Lean how Microsoft Flow and Microsoft Defender ATP integration works in this demo where your SOC team receive a notification email to approve isolating a compromised machine, which triggers Microsoft Defender ATP to isolate the machine, thanks to the integration with Microsoft Flow.
In this demo, you will learn how to create a Microsoft Flow that:
--------------------------------------------------------------------------------------------------
Detects if a High or Medium severity alert occurs in Microsoft Defender ATP.
If that happens, start a workflow approval process that sends email to your SOC team to approve the (Isolate Machine) action from within that email.
Once approved, Microsoft Defender ATP isolates the machine, which helps containing the incident and giving time to your team to investigate the incident.
Microsoft defender ATP and Microsoft flow integration opens the opportunity for many automation scenarios to come. The whole workflow you saw today ensures your security teams are alerted by email at all times about threats across your organization, and they can take actions from within that email whether they are at work, traveling and from their mobile devices.
Full Blog Post:
--------------------------
https://blog.ahasayen.com/ms-flow-and...
Watch
----------
Microsoft Defender ATP and Microsoft Flow Integration Video - How to Isolate a Machine
• Microsoft Flow & MS Defender ATP Integrati...
Read the blog post for this video here:
https://blog.ahasayen.com/ms-flow-and...
MS defender ATP & MS Flow - Restrict App Execution on CEO Machine YouTube Video
• MS defender ATP & MS Flow - Restrict App E...
MS defender ATP & MS Flow - Restrict App Execution on CEO Machine Blog Post
https://blog.ahasayen.com/protect-you...
Connect with me
----------------------------
About me: https://me.ahasayen.com
Blog: https://blog.ahasayen.com
Twitter: / ammarhasayen
LinkedIn: / ammarhasayen
Instagram: / ammarhasayen
SlideShare: https://www.slideshare.net/ammarhasayen
View my Pluralsight course : Implementing Azure AD Privileged Identity Management
https://www.pluralsight.com/courses/m...
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: