Relecloud connects Microsoft Defender XDR to Microsoft Sentinel. An automation rule whose only condition is that the analytics rule name contains the word phishing tags and assigns incidents correctly for incidents that Microsoft Sentinel creates, but never runs for the phishing incidents that arrive from Microsoft Defender XDR. Why?
- A.
Incidents synchronized from Microsoft Defender XDR are not created by a Microsoft Sentinel analytics rule, so the condition never matches
- B.
The Microsoft Defender XDR connector synchronizes incidents only once every 24 hours, so the automation rule expires before those incidents reach the workspace
- C.
Automation rules cannot act on incidents that were created in Microsoft Defender XDR, so a playbook triggered by the Microsoft Defender XDR connector is required instead
- D.
Automation rules that contain an Assign owner action are skipped for incidents whose owner field was already populated by the originating security product
Show answer
Answer: A
An incident that came from Microsoft Defender XDR has no Microsoft Sentinel analytics rule name, so a condition written on that property can never be satisfied.
- A. Synchronized Defender XDR incidents have no Sentinel analytics rule name, so that condition can never match.
- B. Incident synchronization is near real time, not a daily batch.
- C. Automation rules do apply to synchronized Defender XDR incidents; the limitation is invented.
- D. No skip behaviour exists for incidents that already have an owner; the action would simply overwrite it.
