Which table in Sentinel shows information about Devices at risk?

Georgi Palazov 286 Reputation points
2023-06-19T06:25:55.8666667+00:00

Hello,

I'm looking to query the devices at risk which are being reported from Microsoft Endpoint, but I want to query them in Sentinel.

I've looked at different Device* tables, but none give some kind of risk score or a way to identify if the current device is at risk.

Am I missing something?

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,056 Reputation points Microsoft Employee
    2023-06-19T14:54:36.6033333+00:00

    If you look at the DeviceInfo in the MDE advanced hunting there is an Exposure Score in the table. It does not appear that the same column is included in Sentinel. I know there are some other examples of inconsistency with the data connector. I am not sure if this is a bug or if there was a technical reason/blocker.

    You might look into the Sentinel Triage Assistant. It has a module for enriching incidents with MDE data including risk score. https://github.com/briandelmsft/SentinelAutomationModules


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.