Azure Defender Out of the box Rule in Azure Sentinel

Nafila Afrin 111 Reputation points
2021-10-13T08:37:51+00:00

Hi ,

May i know the difference between

  1. Create incidents based on Azure Security Center alerts
  2. Create incidents based on Azure Defender alerts

Both the Microsoft security service is shown as Azure Defender

Thanks in advance!

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Answer accepted by question author
  1. Vipul Sparsh 16,331 Reputation points Microsoft Employee Moderator
    2021-10-13T09:18:51.347+00:00

    @Nafila Afrin Thanks for reaching out.

    The first incident creation rule(Azure security center) is the old one that you see, that has been renamed with Azure Defender now.
    The connector also now has the Azure Defender name updated and the same option will find while creating the analytics rules.

    140080-image.png

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.