
Explore how to use Microsoft Sentinel SOAR with logic apps to automate security orchestration and response. Build solutions from incident notifications to IP blocking, using Teams, email, and third-party connectors.
Explore how logic apps automate, orchestrate, and schedule security workflows within Microsoft Sentinel. Learn to trigger playbooks, integrate with Teams or email notifications, and respond to incidents efficiently.
Create a sentinel logic app that uses the legacy agent to monitor security events, connect to a Windows VM, and automatically shut it down when a specific event ID occurs.
Connect a VM to Microsoft Sentinel, configure a data connector and analytic rule, and trigger a logic app playbook to generate incidents and turn off VM when logs are cleared.
Configure and test a legacy agent security flow in Microsoft Sentinel, linking an incident analytics rule to a VM shutdown playbook via a logic app with explicit permissions and automation.
Automate blocking of malicious IPs in Microsoft Sentinel by ingesting threat intel via the taxi data connector, then add IP ranges to a named location in a conditional access policy.
Practice adding an IP to a named location to block with Microsoft Sentinel, Logic Apps, and Playbooks, including building analytic rules, entity mapping, and incident automation.
Troubleshoot a logic app playbook in Microsoft Sentinel by diagnosing a name location fetch failure, configuring an Azure Active Directory app registration, and granting Graph API permissions.
Explore adding threat intel IP addresses to a named location and blocking access via conditional access policies using Microsoft Sentinel, Logic Apps, and Playbooks.
Enable VirusTotal IP enrichment in the Sentinel playbook by querying IP address reports for each IP and enriching incidents with VirusTotal data to reveal malicious characteristics, enabling automated responses.
Analyze Microsoft Sentinel logs to view enriched IP attributes and last 30 minutes reports, then use enriched data to decide blocking IPs at the firewall.
Design a logic app flow to fetch malicious IP addresses with VirusTotal, block them via firewall policies and IP groups, and notify teams.
Design a logic app flow to automate firewall policy actions, integrate IP groups and custom connectors, and deploy playbooks in Microsoft Sentinel SOAR for incident-driven responses.
Explore how to design and test a logic app flow, trigger incidents via analytics, and use a playbook to block an IP address through a firewall.
Learn to block ip addresses at scale using Microsoft Sentinel soar with Logic Apps and Playbooks, building ip groups and incident workflows via Teams adaptive cards.
Master must-know logic app concepts from a sentinel perspective, including app registration, permissions, secrets, manager entity, and roles like logic app contributor and operator for secure automation.
Automate fetching terminated employee data from an outlook email attachment with a logic app. Store the attachment in blob storage and update the sentinel watch list using a sas url.
Microsoft Sentinel is a Cloud Based SIEM & SOAR Solution which is a Revolutionary Product.
SIEM: Security Information & Event Management.
SOAR: Security Orchestration & Automated Response.
In this Course we will Focus on Understand SOAR, In Sentinel to achieve SOAR we use Logic Apps,
Though the Purview of Logic App is huge we will try to understand How to achieve Sentinel Automation & SOAR aspect.
We have hands on Session in Building Logic App from Scratch and to utilize the one available out of the Box Respectively.
This Course will Enable you to create Logic Apps and server the Automation Application in Sentinel which Microsoft Cloud SIEM Solution.
The SOAR Capability of Microsoft Sentinel has Diverse aspect, and this very Course will enable you start in it with Real world use cases in hand, which indeed can be used directly as an application in your Sentinel Implementation.
The Exercises and Demo Indicated in the Sessions are Reusable and can be implemented in your Azure Environment readily and easily.
You just need a Demo Environment, Sentinel and Log analytics Workspace, which are pre-requisites for this Course
We will build Logic apps from Scratch, Use Out of box Logic Apps to understand the Each Step and Action respectively.