Check out my blog post "Mastering (Orphan) API Connections in Microsoft Sentinel Playbooks" in which I demonstrate how to manage the API connections of your Microsoft Sentinel Playbooks and identify orphaned ones.
blog.ambrozzo.ch/posts/master...
#microsoftsentinel #LogicApps #IaC
29.12.2025 08:37
π 0
π 0
π¬ 0
π 0
Disabling a user account during a security incident removes them from all Microsoft Teams. Private channel membership is not automatically restored. This #KQL query lists all private channels the user was removed from.
github.com/lorisAmbrozz...
07.11.2025 10:06
π 0
π 0
π¬ 0
π 0
While diving into Defender XDR Attack Disruption with x.com/nicolonsky, I noticed that the Enterprise App Microsoft Defender for Identity (formerly Radius Aad Syncer) is responsible for the response actions in Entra ID. The #KQL query lists these actions.
github.com/lorisAmbrozz...
17.04.2025 10:53
π 2
π 0
π¬ 0
π 0
That's a simple one but could be quite useful also in combination with other #detections. π₯Since a few days, it's possible to use #KQL to detect when a global admin elevates access to manage all subscriptions and management groups.
github.com/lorisAmbrozz...
07.02.2025 06:45
π 1
π 0
π¬ 0
π 0
I was wondering the same thing this morning π in one customer environment it is also available and in another tenant, there is still no MDCA available. Let's hope soon π€
11.12.2024 19:09
π 2
π 0
π¬ 1
π 0