Why use Fortinet Connector instead of a Function App for registering an action group in the Fortinet-FortiGate playbook?

mara7 166 Reputation points
2025-02-12T05:09:01.1633333+00:00

Hello,

I am setting up the Fortinet-FortiGate playbook and noticed that for registering an action group in FortiGate, the playbook uses the Fortinet Connector instead of a Function App.

Why was the Fortinet Connector chosen for this action instead of a Function App? Wouldn’t using the Fortinet Connector pose a security risk due to potential API key exposure?

Thank you!

Microsoft Security Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,051 Reputation points Microsoft Employee
    2025-02-12T12:53:32.88+00:00

    I have not deployed this particular connector. There are two options, both used Syslog (CEF) forwarding for data collection. The solutions include logic apps and one function app. Both include or can easily be expanded to use secure API key storage like a Key Vault. I assume there are also ways to limit the key permissions. They appear to be supplemental automation. I recommend deploying the solutions so you can take a closer look followed by a pilot of the agent-base data connector. It is also likely that the solutions were provided by Fortinet rather than Microsoft. Any person or vendor can submit solutions through GitHub for publishing to the solution marketplace after review.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.