Hello everyone !
I have a bidirectional problem with MCAS
Let me explain, when closing an incident (via the MCAS connector) on Azure Sentinel, it is not close on MCAS. I am looking for a way to synchronize MCAS with Azure Sentinel.
I started to do some research to find a solution and here are my leads.
Manual solution
Setting up of a playbook which triggers each time an incident, with the MCAS connector, is closed.
Then, close the incident via MCAS API token.
Native solution
Disable each connector (MDI, MDO, MDE, MCAS) and enable the Microsoft 365 Defender (Preview) connector to centralize everything.
Microsoft 365 Defender is two-way. Pass incidents from MCAS through Defender, will sync Azure Sentinel alert to MCAS ?
However, (according to my research) the M365 Defender connector seems to only include MDE (at the moment). MDI, MDO and MCAS are "soon available".
→ Waiting for a native solution from Microsoft ?
Have you ever encountered this problem ? What solution do you recommend ?
Thanks a lot !